CVE-2026-21625
Description
User provided uploads to the Easy Discuss component for Joomla aren't properly validated. Uploads are purely checked by file extensions, no mime type checks are happening.
CWE
- CWE-434 — CWE-434 Unrestricted Upload of File with Dangerous Type
Affected
- Stackideas.com / EasyDiscuss extension for Joomla — v=1.0.0-5.0.15 [affected]
CVSS
- 4.0 score=4.8 severity=MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:L
References
Source
cvelistV5-main/cves/2026/21xxx/CVE-2026-21625.json