EIP-2026-108242
PRE-CVEJoomla! Component CiviCRM - Multiple Arbitrary File Upload Vulnerabilities
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-108242. PoCs published by Crim3R.
AI-analyzed exploit summary The provided text describes an arbitrary file upload vulnerability in the CiviCRM component for Joomla! due to insufficient input sanitization. It includes example URLs where the vulnerability can be exploited but does not contain functional exploit code.
Description
Joomla! Component CiviCRM - Multiple Arbitrary File Upload Vulnerabilities
Exploits (1)
exploitdb
WRITEUP
VERIFIED
by Crim3R · textwebappsphp
https://www.exploit-db.com/exploits/37648
The provided text describes an arbitrary file upload vulnerability in the CiviCRM component for Joomla! due to insufficient input sanitization. It includes example URLs where the vulnerability can be exploited but does not contain functional exploit code.
Classification
Writeup 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target:
CiviCRM component for Joomla!
No auth needed
Prerequisites:
Access to the vulnerable Joomla! instance with CiviCRM installed
MITRE ATT&CK
devstral-2 · analyzed Feb 18, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026