CVE-2018-6580: Janguo Jimtawl

Critical severity, CVSS 9.8. EPSS: 36.3% chance of exploitation in the next 30 days.

Arbitrary file upload exists in the Jimtawl 2.1.6 and 2.2.5 component for Joomla! via a view=upload&task=upload&pop=true&tmpl=component request.

Affected products

  • Janguo Jimtawl: version 2.1.6 only; version 2.2.5 only

Published 2018-02-02. Last modified 2026-06-17.