CVE-2026-21625

All FrameworksJoomlaCWE-434CVE-2026-21625

CVE-2026-21625

State: PUBLISHED · Published: 2026-01-16 · Updated: 2026-01-16 · Assigner: Joomla
Description
User provided uploads to the Easy Discuss component for Joomla aren't properly validated. Uploads are purely checked by file extensions, no mime type checks are happening.
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2026/21xxx/CVE-2026-21625.json