PT-2026-3256 · Joomla · Easydiscuss

Simoni

·

Published

2026-01-16

·

Updated

2026-01-16

·

CVE-2026-21625

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Easy Discuss component for Joomla (affected versions not specified)
Description User-provided uploads to the Easy Discuss component for Joomla are not properly validated. The component relies solely on file extensions for validation, lacking any checks for MIME types. This could allow for the upload of malicious files disguised with legitimate extensions.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2026-21625

Affected Products

Easydiscuss