CVE-2026-62415: Joomla Membership Pro Allows Unauthenticated File Upload
ID: 9892c8ab-e866-5efc-8806-9c341663341b
STIX ID: report--9892c8ab-e866-5efc-8806-9c341663341b
Feed Name: CosmicBytez Labs
Threat Score
A critical unauthenticated file upload vulnerability (CVE-2026-62415, CVSS 9.1) in Joomla Membership Pro versions prior to 4.6.2 allows unauthenticated attackers to upload arbitrary files (including PHP webshells) to internet-facing sites; the report includes exploitation steps, detection indicators, and remediation guidance (upgrade to 4.6.2, scan for webshells, and apply server-level restrictions).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
