CVE-2026-61900: Dj-Extensions.com Jdownloads Extension For Joomla

Critical severity, CVSS 10.0. EPSS: 0.4% chance of exploitation in the next 30 days.

Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-jDownloads < 4.1.6 - The Joomla extension JDownloads is vulnerable to an unauthenticated file upload, leading to full RCE.

Affected products

Published 2026-07-20. Last modified 2026-07-23.