CVE-2026-21625

Severity CVSS v4.0:
MEDIUM
Type:
CWE-434 Unrestricted Upload of File with Dangerous Type
Publication date:
16/01/2026
Last modified:
16/01/2026

Description

User provided uploads to the Easy Discuss component for Joomla aren't properly validated. Uploads are purely checked by file extensions, no mime type checks are happening.

References to Advisories, Solutions, and Tools