CVE-2026-21625
HIGHStackideas Easydiscuss < 5.0.15 - Unrestricted File Upload
Title source: ruleDescription
User provided uploads to the Easy Discuss component for Joomla aren't properly validated. Uploads are purely checked by file extensions, no mime type checks are happening.
References (1)
Scores
CVSS v3
8.8
EPSS
0.0002
EPSS Percentile
6.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-434
Status
published
Products (1)
stackideas/easydiscuss
1.0.0 - 5.0.15
Published
Jan 16, 2026
Tracked Since
Feb 18, 2026