CVE-2026-73373
Analyzed Analyzed - Analysis Complete

Unrestricted SHTML File Upload in Joomla Core

Vulnerability report for CVE-2026-73373, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-18

Last updated on: 2026-09-03

Assigner: Joomla! Project

Description

Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.2 - The default list of dangerous files did not include SHTML files. On servers that executed these files, that could lead to code execution.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-18
Last Modified
2026-09-03
Generated
2026-09-07
AI Q&A
2026-08-18
EPSS Evaluated
2026-09-06
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
joomla joomla! From 6.0.0 (inc) to 6.1.3 (exc)
joomla joomla! From 1.0.0 (inc) to 5.4.8 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-434 The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows unrestricted uploads of SHTML files in Joomla versions 1.0.0-5.4.7 and 6.0.0-6.1.2. SHTML files can be executed on servers that support them, potentially leading to remote code execution. The default list of dangerous file types did not include SHTML files.

Detection Guidance

Check Joomla versions with commands like 'composer show joomla/joomla' or 'php -r "echo JVERSION;". Look for SHTML files in upload directories. Review server logs for unexpected SHTML file executions.

Impact Analysis

An attacker could upload malicious SHTML files to your Joomla site. If your server executes these files, it could lead to unauthorized code execution, allowing the attacker to take control of your server or steal data.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR and HIPAA requirements for data protection and confidentiality. Non-compliance may result in legal penalties and reputational damage.

Mitigation Strategies

Upgrade Joomla to versions 5.4.8 or 6.1.3 immediately. Remove or restrict SHTML file uploads in Joomla configuration. Block SHTML execution in server settings like Apache's httpd.conf or .htaccess.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-73373. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart