Skip to content
Critical Joomla Plugin Vulnerabilities Exploited

Critical Joomla Plugin Vulnerabilities Exploited

First seen 26 Sep 2026, 21:51 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 27, 2026 at 18:20 UTC
  • •Three critical vulnerabilities in Joomla's Universal Plugin allow severe attacks.
  • •Exploits include unauthorized PHP execution, file reading, and remote code installation.
  • •Patches are available; affected users must update to versions 6.1.0 or 5.2.1 immediately.

Three critical vulnerabilities (CVE-2026-97160, CVE-2026-97161, CVE-2026-97163) affecting the Universal Plugin for Joomla have been disclosed, allowing unauthorized PHP code execution, path traversal, and remote code installation. These vulnerabilities impact versions 5.0.0 to 5.2.0 and 6.0.0 to 6.0.29 of the plugin. Attackers can exploit these flaws via AJAX handlers and GitHub action downloads, potentially compromising server integrity and confidentiality. The vulnerabilities have been assigned high CVSS scores, with CVE-2026-97160 rated at 9.4, CVE-2026-97161 at 9.2, and CVE-2026-97163 at 10.0. Patches are available in versions 6.1.0 and 5.2.1. The first public proof-of-concept (PoC) code for these vulnerabilities was released on September 27, 2026, heightening the urgency for affected users to update their systems.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-26
CVE-2026-97160 published
CVE-2026-97160 disclosed, allowing PHP code injection via shortcodes in Joomla's UP plugin.
Article 3 (Sploitus)
2026-09-26
CVE-2026-97161 published
CVE-2026-97161 disclosed, enabling unauthenticated path traversal and file read in Joomla's UP plugin.
Article 2 (Sploitus)
2026-09-26
CVE-2026-97163 published
CVE-2026-97163 disclosed, allowing unauthenticated remote code installation via GitHub actions in Joomla's UP plugin.
Article 1 (Sploitus)
2026-09-26
CVE-2026-97162 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-27
First public PoC released
Public proof-of-concept code for CVE-2026-97160, CVE-2026-97161, and CVE-2026-97163 made available, increasing exploitation risk.
Article 1 (Sploitus)

More articles in this cluster (3)

Following this threat?

Track CVE-2026-97160 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed