The Joomla extension RSFiles is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
[POC] GHSA-8gj2-2cvc-6xx7 — rsfiles-CVE-2026-57827
Unauthenticated File Upload → RCE PoC for CVE-2026-57827 (RSFiles! Joomla < 1.17.12). Authorized security research use only.
[POC] GHSA-3whf-vgf2-9w6g — CVE-2026-57827
Demonstrate the unauthenticated remote code execution vulnerability in the RSFiles! Joomla component through an arbitrary file upload.
[POC] GHSA-3whf-vgf2-9w6g — CVE-2026-57827
CVE-2026-57827 — RSFiles! Joomla Component Unauthenticated File Upload RCE. Split-controller upload bypass. CVSS 9.8 | CWE-434 | com_rsfiles < 1.17.12
PoC: CVE-2026-57827
Joomla RSFiles 未授权文件上传CVE-2026-57827检测&利用脚本
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free