CVE-2026-61900: Dj-Extensions.com Jdownloads Extension For Joomla
Critical severity, CVSS 10.0. EPSS: 0.4% chance of exploitation in the next 30 days.
Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-jDownloads < 4.1.6 - The Joomla extension JDownloads is vulnerable to an unauthenticated file upload, leading to full RCE.
Affected products
- Dj-Extensions.com Jdownloads Extension For Joomla: version 4.1.0-4.1.5 only
Published 2026-07-20. Last modified 2026-07-23.