Joomla扩展 - lomart.fr - 在UP插件扩展5.0.0-5.2.0和6.0.0-6.0.29版本中,存在经过身份验证且拥有权限的PHP命令注入漏洞。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| lomart.fr | UP plugin for Joomla | 5.0.0-5.2.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-97163 | 10.0 CRITICAL | Joomla Extension - lomart.fr - Unauthenticated remote code installation in UP plugin exten |
| CVE-2026-97161 | 9.2 CRITICAL | Joomla Extension - lomart.fr - Various path traversal / file access vectors in UP plugin e |
| CVE-2026-97162 | 8.3 HIGH | Joomla Extension - lomart.fr - Various SQL injection vectors in UP plugin extension 5.0.0- |
No comments yet