CVE-2026-61424
The Joomla extension DJ-Classifieds (versions prior to 3.11.2) contains an unauthenticated arbitrary file upload vulnerability (CWE-434) that allows attackers to upload malicious files and achieve remote code execution. This flaw is rated critical with a CVSS base score of 10. No official fix or known exploitation details are provided in the sources.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Users of the DJ-Classifieds Joomla extension running versions earlier than 3.11.2.
Real-world impact
An attacker can upload and execute arbitrary code on the server without authentication, potentially leading to full compromise of the affected site.
Why this severity
CVSS 4.0 metrics show attack vector network, low attack complexity, no privileges or user interaction required, and high impact on confidentiality, integrity, and availability, resulting in a maximum score of 10.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources
Timeline
- Jul 20, 2026 · 13d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 23, 2026 · 10d agoAdvisory updatedThe NVD record was last revised.