CVE-2026-97160

LOWCVSS 9.4 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Joomla Extension - lomart.fr - Authenticated, privileged PHP command injection in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29

0.0/ 10 priority

Sources & remediation

Other references
Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked 1d ago at 2 mentions (2026-09-26); latest day: 2
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-09-26: 2Mentions · 2026-09-27: 209-2609-27
Referenced assets4 URLs
Full discourse4 posts
  • Rıdvan Yağlı@ridvanyagli

    🔴 Joomla eklentilerinde kritik güvenlik açıkları! Joomla ekosisteminde çok sayıda önemli / kritik güvenlik açığı yayınlandı. CVE-2026-97163 — CVSS 10.0 Critical : UP Universal Plugin — Uzaktan kod yükleme / çalıştırma CVE-2026-97160 — CVSS 9.4 Critical : UP Universal Plugin — PHP command injection CVE-2026-97161 — CVSS 9.2 Critical : UP Universal Plugin — Path Traversal / yetkisiz dosya erişimi CVE-2026-94132 — CVSS 9.5 Critical : AcyMailing Enterprise < 11.1.0 — RCE CVE-2026-94131 — CVSS 8.3 High : AcyMailing Enterprise < 11.1.0 — Yetkisiz dosya silme 📌 UP Universal Plugin: Etkilenen sürümler için UP 6.1.0 / eski Joomla serileri için 5.2.1 sürümüne güncellenmesi öneriliyor. 📌 AcyMailing Enterprise: 11.1.0 veya üzeri sürüme güncellenmeli. ⚠️ Sunucularınızdaki Joomla eklentilerini ve sürümlerini kontrol edin.

    00073473
    2.4K followersView on X
  • mürrez@murrezsec

    New PoC released! 🚀 Check out the analysis details and working exploit code for CVE-2026-97160: 🔗 https://pocbit.org/pocs/cve-2026-97160 #CyberSecurity #SecOps #InfoSec #CVE #PoC

    0003088
    607 followersView on X
  • CVE@CVEnew

    CVE-2026-97160 Joomla Extension - https://lomart.fr - Authenticated, privileged PHP command injection in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29 https://www.cve.org/CVERecord?id=CVE-2026-97160

    00000485
    58.1K followersView on X
  • Manage Multiple WordPress and Joomla Sites easily!@mysitesguru

    We found a way to read any Joomla site's configuration.php through the UP plugin, with no login. UP 6.1.0 fixes it and three more, now CVE-2026-97160 to 97163. https://mysites.guru/blog/up-plugin-joomla-unauthenticated-vulnerabilities/?utm_source=twitter&utm_medium=social https://t.co/Lv9HqeKSra

    0000080
    2.6K followersView on X

Explore more