ZeroHour

CVE-2026-73373

mass

Unrestricted SHTML upload leading to server code execution in Joomla CMS

CVSS 4.0
8.9 high
EPSS
<1%p29
Published
()
Modified
AI analysis

Joomla CMS's default upload filter omitted SHTML files from its list of dangerous file types, allowing users with upload privileges (typically administrator-level, per the privileged-requirement metric in the CVSS 4.0 vector) to place .shtml files on the server. On web servers configured to execute SHTML files (e.g., Apache with server-side includes enabled), an uploaded .shtml file is executed when accessed, giving the attacker server-side code execution on the host. The high subsequent-system impact ratings in the CVSS 4.0 score indicate the compromise can extend beyond the web application itself depending on server configuration. Affected versions span essentially Joomla's entire history: 1.0.0 through 5.4.7 and 6.0.0 through 6.1.2, so virtually every current Joomla installation is in scope, though only hosts that actually execute .shtml are exposed to code execution. No public proof-of-concept or in-the-wild exploitation is known; EPSS currently estimates a 0.4% probability of exploitation within 30 days (29th percentile) and the flaw is not on the CISA KEV list.

What to do: Upgrade all Joomla sites to the first patched release after 5.4.7 (5.x line) and after 6.1.2 (6.x line) once available. Until then, restrict upload capability to trusted administrators and review media/upload directories for unexpected .shtml files. Also confirm whether your web server executes .shtml files (e.g., Apache with server-side includes enabled), since hosts that only store but never execute them carry little code-execution risk.

Affected
Joomla! (all lines through 5.x)1.0.0 - 5.4.7
Joomla! (6.x line)6.0.0 - 6.1.2
Estimated exposure
mass~1M+ active Joomla installations, with hundreds of thousands internet-exposed (every version since 1.0.0 is affected) — Public web-technology surveys and internet-wide scans consistently rank Joomla among the top open-source CMSs, counting hundreds of thousands of reachable Joomla sites and on the order of a million or more active installations, and the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.2 - The default list of dangerous files did not include SHTML files. On servers that executed these files, that could lead to code execution.

Vendors
joomla
Products
joomla\!
Ecosystems
Joomla
Weakness
CWE-434
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

[20260810] - Core - Unrestricted uploads of SHTML files

Joomla fixed CVE-2026-73373, an unrestricted SHTML file upload flaw affecting CMS 1.0.0-5.4.7 and 6.0.0-6.1.2 that can enable code execution.

Joomla published security advisory 20260810 for CVE-2026-73373, an unrestricted upload of files with dangerous type in Joomla CMS. The default dangerous-file list omitted SHTML files, which could lead to code execution on servers that execute SHTML. Affected versions are 1.0.0-5.4.7 and 6.0.0-6.1.2; fixes ship in 5.4.8 and 6.1.3. The issue was reported by Valentin Lobstein (Chocapikk) on 2026-07-29.

Joomla Security Centre · 29d agoAdvisoryCVE-2026-73373