Junglewise Threat Intelligence

CVE-2026-60033: ThemeXpert JMedia SSRF in remote-URL download

CVE-2026-60033 · Severity: info · CVSS 5.1 · Published 2026-07-20

Executive brief

JMedia is a media management extension for the Joomla content management system that allows users to organize and upload files. A security vulnerability in the remote-URL download feature allows high-privileged users to make the server request internal or restricted web addresses. This could be used to probe internal network services or bypass security controls that are not intended to be accessible from the public internet.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in the JMedia extension (versions 1.0 through 1.5.4) for Joomla. The vulnerability is located in the 'Upload from URL' functionality, which fails to properly validate or restrict the destination of remote-URL download requests. An attacker with high privileges (PR:H) can provide a URL pointing to internal or reserved IP addresses, causing the server to perform unauthorized requests. This can lead to internal port scanning or interaction with other services residing on the local network that are otherwise unreachable from the internet. The vulnerability is tracked as CWE-918.

Affected products

  • themexpert.com JMedia extension for Joomla 1.0-1.5.4

Timeline

  • 2026-07-20: advisory: CVE-2026-60033 published by the Joomla! Project

References