Junglewise Threat Intelligence

CVE-2026-97160: Joomla UP plugin PHP command injection

CVE-2026-97160 · Severity: info · Published 2026-09-26

Executive brief

The UP plugin for Joomla is a Joomla extension that allows authorized administrators to perform system tasks. An authenticated administrator with privileges can inject and execute arbitrary PHP commands through the plugin, potentially compromising the entire Joomla installation and underlying server.

Technical details

A PHP command injection vulnerability exists in the UP plugin for Joomla versions 5.0.0-5.2.0 and 6.0.0-6.0.29. The vulnerability requires authentication and administrative privileges to exploit. An attacker with these credentials can inject malicious PHP code that executes with server-level privileges, leading to full system compromise.

Affected products

  • lomart.fr UP plugin 5.0.0-5.2.0, 6.0.0-6.0.29

Timeline

  • 2026-09-26: disclosed

References

Related threats