CVE-2026-66914: Seblod.com Seblod Extension For Joomla
Critical severity, CVSS 9.2. EPSS: 0.5% chance of exploitation in the next 30 days.
Joomla Extension - seblod.com - Unauthenticated path traversal in SEBLOD < 3.30.0, < 4.7.0, < 6.0.1 - An unauthenticated attacker could download files from both inside and outside the webroot.
Affected products
- Seblod.com Seblod Extension For Joomla: version 1.0.0-3.29.0 only; version 4.0.0-4.6.0 only; version 5.0.0-6.0.0 only
Published 2026-08-07. Last modified 2026-08-26.