logo

CVE-2026-62415: Joomla Membership Pro Allows Unauthenticated File Upload

ID: 9892c8ab-e866-5efc-8806-9c341663341b

STIX ID: report--9892c8ab-e866-5efc-8806-9c341663341b

Feed Name: CosmicBytez Labs

Threat Score
80/100

Date Published: 2026-07-22

Date Updated: 2026-07-22

...
...

A critical unauthenticated file upload vulnerability (CVE-2026-62415, CVSS 9.1) in Joomla Membership Pro versions prior to 4.6.2 allows unauthenticated attackers to upload arbitrary files (including PHP webshells) to internet-facing sites; the report includes exploitation steps, detection indicators, and remediation guidance (upgrade to 4.6.2, scan for webshells, and apply server-level restrictions).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.