EIP-2026-108491

PRE-CVE

Joomla! Component com_poweradmin 2.3.0 - Multiple Vulnerabilities

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-108491. PoCs published by RatioSec Research.

AI-analyzed exploit summary The exploit demonstrates a CSRF vulnerability in JSN PowerAdmin Joomla! Extension that allows an authenticated user to upload a malicious PHP file via a crafted HTTP request, bypassing file validation checks. Additionally, it includes an XSS vulnerability that can execute arbitrary JavaScript in the context of an administrator's session.

Description

Joomla! Component com_poweradmin 2.3.0 - Multiple Vulnerabilities

Exploits (1)

exploitdb WORKING POC
by RatioSec Research · textwebappsphp
https://www.exploit-db.com/exploits/39506

The exploit demonstrates a CSRF vulnerability in JSN PowerAdmin Joomla! Extension that allows an authenticated user to upload a malicious PHP file via a crafted HTTP request, bypassing file validation checks. Additionally, it includes an XSS vulnerability that can execute arbitrary JavaScript in the context of an administrator's session.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: JSN PowerAdmin Joomla! Extension 2.3.0
Auth required
Prerequisites: Authenticated user session · Victim must visit a malicious webpage
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026