[20260810] - Core - Unrestricted uploads of SHTML files
Joomla fixed CVE-2026-73373, an unrestricted SHTML file upload flaw affecting CMS 1.0.0-5.4.7 and 6.0.0-6.1.2 that can enable code execution.
Joomla published security advisory 20260810 for CVE-2026-73373, an unrestricted upload of files with dangerous type in Joomla CMS. The default dangerous-file list omitted SHTML files, which could lead to code execution on servers that execute SHTML. Affected versions are 1.0.0-5.4.7 and 6.0.0-6.1.2; fixes ship in 5.4.8 and 6.1.3. The issue was reported by Valentin Lobstein (Chocapikk) on 2026-07-29.
- Default dangerous-file list omitted SHTML files
- Could allow code execution on servers that execute SHTML
- Fixed in Joomla CMS 5.4.8 and 6.1.3
- Reported by Valentin Lobstein (Chocapikk) on 2026-07-29
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-73373 | Unrestricted SHTML upload leading to server code execution in Joomla CMS Joomla CMS's default upload filter omitted SHTML files from its list of dangerous file types, allowing users with upload privileges (typically administrator-level, per the privileged-requirement metric in the CVSS 4.0 vector) to place .shtml files on the server. On web servers configured to execute SHTML files (e.g., Apache with server-side includes enabled), an uploaded .shtml file is executed when accessed, giving the attacker server-side code execution on the host. The high subsequent-system impact ratings in the CVSS 4.0 score indicate the compromise can extend beyond the web application itself depending on server configuration. Affected versions span essentially Joomla's entire history: 1.0.0 through 5.4.7 and 6.0.0 through 6.1.2, so virtually every current Joomla installation is in scope, though only hosts that actually execute .shtml are exposed to code execution. No public proof-of-concept or in-the-wild exploitation is known; EPSS currently estimates a 0.4% probability of exploitation within 30 days (29th percentile) and the flaw is not on the CISA KEV list. Do: Upgrade all Joomla sites to the first patched release after 5.4.7 (5.x line) and after 6.1.2 (6.x line) once available. Until then, restrict upload capability to trusted administrators and review media/upload directories for unexpected .shtml files. Also confirm whether your web server executes .shtml files (e.g., Apache with server-side includes enabled), since hosts that only store but never execute them carry little code-execution risk. | 8.9 | <1% |
| mass~1M+ active Joomla installations, with hundreds of thousands internet-exposed (every version since 1.0.0 is affected) |
Project: Joomla! SubProject: CMS Impact: High Severity: Low Probability: Low Versions: 1.0.0-5.4.7,6.0.0-6.1.2 Exploit type: Unrestricted Upload of File with Dangerous Type Reported Date: 2026-07-29 Fixed Date: 2026-08-18 CVE Number: CVE-2026-73373 Description The default list of dangerous files did not include SHTML files. On servers that executed these files, that could lead to code execution. Affected Installs Joomla! CMS versions 1.0.0-5.4.7, 6.0.0-6.1.2 Solution Upgrade to version 5.4.8, 6.1.3 Contact The JSST at the Joomla! Security Centre. Reported By: Valentin Lobstein (Chocapikk)
This source does not provide full text. Read it at developer.joomla.org.