EIP-2026-108714
PRE-CVEJoomla! Component JE Story Submit - 'index.php' Arbitrary File Upload
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-108714. PoCs published by Robert Cooper.
AI-analyzed exploit summary The provided text describes a file upload vulnerability in the 'com_jesubmit' component for Joomla! due to insufficient input sanitization. It allows arbitrary file uploads, potentially leading to remote code execution (RCE) in the context of the webserver process.
Description
Joomla! Component JE Story Submit - 'index.php' Arbitrary File Upload
Exploits (1)
exploitdb
WRITEUP
VERIFIED
by Robert Cooper · textwebappsphp
https://www.exploit-db.com/exploits/36624
The provided text describes a file upload vulnerability in the 'com_jesubmit' component for Joomla! due to insufficient input sanitization. It allows arbitrary file uploads, potentially leading to remote code execution (RCE) in the context of the webserver process.
Classification
Writeup 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target:
Joomla! with 'com_jesubmit' component
No auth needed
Prerequisites:
Access to the vulnerable Joomla! instance · Network connectivity to the target
MITRE ATT&CK
devstral-2 · analyzed Feb 18, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026