CVE-2026-57828 — Phoca Download: The Joomla extension Phoca Downloads is vulnerable to an authenticated arbitrary file upload that
The Joomla extension Phoca Downloads is vulnerable to an authenticated arbitrary file upload that allows registered users uploading executable files and leads to full RCE. CVSSv3.1 8.8 (HIGH) · EPSS 17th percentile