Showing 1 vulnerability on this page for Joomla! CMS

Signals CISA KEV Ransomware Nuclei
Joomla vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Joomla 6.1.1 Zip Slip Path Traversal via com_joomlaupdate extract.php

Joomla 6.1.1 contains a path traversal vulnerability in the com_joomlaupdate extension that allows a Super User to be induced into extracting a crafted archive containing directory traversal sequences or absolute paths in ZIP entry filenames. Attackers can supply malicious ZIP entry names with parent-directory segments or absolute paths to the extract.php extraction routine, causing files to be written outside the intended destination root and enabling persistent remote code execution via plante

CWE-22Aug 12, 2026
CVSS8.7v4.0EPSS0.853%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX