CVE-2026-57827: Rsjoomla Rsfiles!

Critical severity, CVSS 9.8. EPSS: 2.3% chance of exploitation in the next 30 days.

Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12 - The Joomla extension RSFiles is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

Affected products

  • Rsjoomla Rsfiles!: before 1.17.12 (fixed in 1.17.12)

Published 2026-07-11. Last modified 2026-07-23.