CVE-2026-97160: Lomart.fr Up Plugin For Joomla

Critical severity, CVSS 9.4. EPSS: 1.3% chance of exploitation in the next 30 days.

Joomla Extension - lomart.fr - Authenticated, privileged PHP command injection in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29

Affected products

  • Lomart.fr Up Plugin For Joomla: version 5.0.0-5.2.0 only; version 6.0.0-6.0.29 only

Published 2026-09-26. Last modified 2026-09-29.