CVE-2026-21625: Stackideas Easydiscuss

High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.

User provided uploads to the Easy Discuss component for Joomla aren't properly validated. Uploads are purely checked by file extensions, no mime type checks are happening.

Affected products

  • Stackideas Easydiscuss: from 1.0.0, up to and including 5.0.15

Published 2026-01-16. Last modified 2026-06-17.