---
schema: 1
kind: vulnerability
title: "Joomla file-upload RCE wave adds RSFiles! (CVE-2026-57827, unauth, CVSS 10.0) and Phoca Download (CVE-2026-57828, CVSS 9.0)"
headline: "Two more Joomla extensions patch file-upload-to-RCE flaws — RSFiles! is reachable with no login at all (CVSS 10.0)"
summary: >
  Two more Joomla third-party extensions from the same researcher-driven disclosure wave patched
  arbitrary-file-upload-to-RCE flaws on 2026-07-10: RSFiles! (com_rsfiles) up to 1.17.11 lets any
  unauthenticated visitor upload and execute a .php file in its web-root downloads folder
  (CVE-2026-57827, CVSS 4.0 10.0, fixed 1.17.12), and Phoca Download (com_phocadownload) up to 6.1.2
  lets a logged-in member bypass the file-type allow-list on its non-default member-upload feature
  (CVE-2026-57828, CVSS 4.0 9.0, fixed 6.1.3). No public PoC and no confirmed exploitation of these two
  yet, but earlier members of this exact CWE-434 wave reached CISA KEV within days — any Swiss/EU
  municipal or public-sector Joomla site running these extensions should update now and hunt for web shells.
discovered_at: "2026-07-11T13:00:00Z"
event_date: "2026-07-10"
run_id: 2026-07-11T1210Z-intel
priority: high
immediate_action: null
tags: [vulnerabilities, rce, pre-auth, patch-available]
regions: [global, europe, switzerland]
sectors: [public-sector]
entities: [trend:joomla-extension-file-upload-rce-wave]
techniques: [T1190, T1505.003]
affected_products: ["RSFiles! for Joomla", "Phoca Download for Joomla"]
cves:
  - id: CVE-2026-57827
    cvss: "10.0"
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status: [patch-available]
    affected: "≤ 1.17.11"
    fixed: "1.17.12"
  - id: CVE-2026-57828
    cvss: "9.0"
    epss: null
    type: rce
    vector: zero-click
    auth: post-auth
    status: [patch-available]
    affected: "≤ 6.1.2"
    fixed: "6.1.3"
sources:
  - url: "https://mysites.guru/blog/rsfiles-unauthenticated-file-upload-rce/"
    publisher: "mySites.guru"
    date: "2026-07-10"
    role: primary
  - url: "https://www.rsjoomla.com/blog/view/644-unauthenticated-file-upload-fixed-in-rsfiles-version-11712-update-now.html"
    publisher: "RSJoomla! (vendor)"
    date: "2026-07-10"
    role: corroborating
  - url: "https://mysites.guru/blog/phoca-download-authenticated-file-upload-rce/"
    publisher: "mySites.guru"
    date: "2026-07-10"
    role: primary
  - url: "https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json"
    publisher: "CISA KEV"
    date: "2026-07-10"
    role: corroborating
closed_sources: []
evidence:
  - quote: "any attacker, without having an account on your website, can upload a .php file in your /downloads directory and execute it."
    publisher: "RSJoomla! (vendor advisory, quoted by mySites.guru)"
  - quote: "A logged-in user could upload a file type that should have been rejected, such as a `.php` script, into the public user-upload folder and then run it."
    publisher: "mySites.guru"
verification: multi-source
sourcing_note: "RSFiles! (CVE-2026-57827) is corroborated by the vendor RSJoomla!'s own advisory alongside the discoverer mySites.guru; Phoca Download (CVE-2026-57828) rests on the discoverer's write-up plus the vendor 6.1.3 fix, with the CVE assignment (Joomla project CNA) and CVSS 9.0 verified against the authoritative CVE record. No proof-of-concept has been published for either; the mySites.guru posts deliberately withhold the exploit request."
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
classification:
  reliability: B
  credibility: 2
watchlist_hit: false
actions:
  - "Update RSFiles! (com_rsfiles) to ≥ 1.17.12 on every Joomla site now — this is unauthenticated RCE reachable by anyone, not a maintenance-window update — then check the component's web-root /downloads directory for stray .php/.phtml files and review admin accounts for tampering."
  - "Update Phoca Download (com_phocadownload) to ≥ 6.1.3; if the frontend member-upload feature was enabled (it is off by default), treat as a priority and hunt the user-upload folder for web shells. Disable member-upload where not required to remove the exposure entirely."
  - "As defense-in-depth against the whole wave, configure the web server to deny script execution in Joomla extension upload/download directories."
updates:
  - at: "2026-09-29T23:36:08Z"
    run_id: 2026-09-29T2134Z-audit
    type: improvement
    internal: true
    summary: >
      Citations realigned so each CVE identifier cites a page that carries it: the RSFiles! CVE and
      score now cite mySites.guru rather than the vendor post, which gives neither, and the four
      earlier extensions' CVE identifiers cite CISA's KEV catalog, which lists all four (two added
      2026-07-07, two 2026-07-10) where the earlier wording said several. The entry's own findings are
      unchanged. The poc-public tag is removed, since mySites.guru states no proof of concept has been
      made public, and the exploitation of the four earlier extensions is cited to the KEV catalog
      rather than to the RSFiles post.
    fields: [sources, tags, body]
migrated_from: null
---

Two more third-party Joomla extensions have patched unrestricted-file-upload flaws that end in remote code execution, both disclosed and fixed on 2026-07-10 by the same researcher (Phil Taylor of mySites.guru) whose source-code audits have been driving an ongoing wave of the identical CWE-434 bug class across the Joomla extension ecosystem. In **RSFiles!** (`com_rsfiles`) through 1.17.11, the permission gate and file-type allow-list live in a pre-flight method while the method that actually writes the upload to disk performs no permission check and no extension check; because that write method can be called directly with no site-wide CSRF token and no access check, an anonymous visitor bypasses the gate entirely, and RSFiles!'s default downloads folder sits inside the web root with PHP execution enabled (the protective `.htaccess` is an opt-in setting that is off by default) — so a `.php` upload lands in a directory that executes it, giving unauthenticated RCE (CVE-2026-57827, CVSS 4.0 10.0) ([mySites.guru, 2026-07-10](https://mysites.guru/blog/rsfiles-unauthenticated-file-upload-rce/)). The vendor RSJoomla! shipped 1.17.12 the same day, ["update NOW!"](https://www.rsjoomla.com/blog/view/644-unauthenticated-file-upload-fixed-in-rsfiles-version-11712-update-now.html). In **Phoca Download** (`com_phocadownload`) through 6.1.2, the non-default frontend member-upload feature runs under a different internal upload mode than the one the allow-list check was written for, so the configured file-type restriction is never consulted and a registered member can upload and execute a `.php` file into the public user-upload folder — authenticated RCE that requires an account plus the member-upload feature enabled (CVE-2026-57828, CVSS 4.0 9.0, fixed in 6.1.3) ([mySites.guru, 2026-07-10](https://mysites.guru/blog/phoca-download-authenticated-file-upload-rce/)).

Neither flaw has a published proof-of-concept and neither is confirmed exploited yet, but the wave's earlier members have a short track record from disclosure to in-the-wild abuse: JoomShaper SP Page Builder, Joomlack Page Builder CK, Balbooa Forms and iCagenda all carry the same unauthenticated-or-low-auth file-upload primitive ([mySites.guru, 2026-07-10](https://mysites.guru/blog/rsfiles-unauthenticated-file-upload-rce/)). All four were exploited, and CISA added them to its KEV catalog within days: CVE-2026-48908 (SP Page Builder) and CVE-2026-56290 (Page Builder CK) on 2026-07-07, CVE-2026-48939 (iCagenda) and CVE-2026-56291 (Balbooa Forms) on 2026-07-10 ([CISA KEV](https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json)). Joomla is heavily used across Swiss and European municipal and public-sector websites, and extension-level exposure is independent of core-Joomla patch status, so an otherwise up-to-date site can still be exposed through either component.

**Detection:** in web-access logs, hunt POST requests to these components' frontend upload endpoints (com_rsfiles upload tasks; com_phocadownload member-upload) and, in the filesystem, alert on new `.php`/`.phtml`/`.php5` files appearing under extension download/upload directories inside the web root — the classic web-shell-staging signal. The benign-lookalike discriminator is the session context: legitimate upload traffic always carries a valid Joomla session cookie and a CSRF token matching that session, whereas the RSFiles! exploit path reaches the write function anonymously with no token, and the Phoca path reaches a write mode the allow-list never guarded; either an upload with no matching session/token or an executable file type landing in a public directory is the anomaly to chase.
