Joomla <6.1.2 - Unrestricted SHTML Upload (LFE)
CVE-2026-73373 Published on August 18, 2026

Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.2
Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.2 - The default list of dangerous files did not include SHTML files. On servers that executed these files, that could lead to code execution.

Vendor Advisory NVD

Vulnerability Analysis

CVE-2026-73373 can be exploited with network access, and requires user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.

Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
HIGH
User Interaction:
NONE

Weakness Type

What is an Unrestricted File Upload Vulnerability?

The software allows the attacker to upload or transfer files of dangerous types that can be automatically processed within the product's environment.

CVE-2026-73373 has been classified to as an Unrestricted File Upload vulnerability or weakness.


Products Associated with CVE-2026-73373

Want to know whenever a new CVE is published for Joomla? stack.watch will email you.

 

Affected Versions

Joomla! Project Joomla! CMS: Joomla! Project Joomla! Framework Filesystem package: