CVE•Published 2026-07-11•Modified 2026-07-23•1 article on news•5 live references•NVD data
CVE-2026-57827Rsjoomla · Rsfiles\!
Vulnerability data via NVD (ingested)
CVSS v3.1
9.8
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS percentile
25
Exploit Prediction Scoring System · top 75% of all CVEs
Weaknesses (CWE)
Description
Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12 - The Joomla extension RSFiles is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
Timeline
Published 2026-07-11
Modified 2026-07-23
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common). Live host counts are a Premium feature.
Shodan · vuln tag
vuln:CVE-2026-57827Hosts Shodan has explicitly fingerprinted as vulnerable.
Shodan · product
product:"Rsjoomla Rsfiles\!"All exposed Rsjoomla Rsfiles\! instances — cross-reference with the CVE's affected-version range.
Shodan · banner/body mention
http.html:"Rsfiles\!"HTTP body or banner mentions "Rsfiles\!" — catches deploys Shodan didn't identify as a product.
More intel sources (5)
Shodan report
vuln:CVE-2026-57827Country / ASN / product breakdown for the vuln query.
Censys
vulnerabilities.cve_id: CVE-2026-57827Censys host search filtered to this CVE id.
grep.app
CVE-2026-57827Public source-code mentions — fast PoC discovery.
GitHub code
CVE-2026-57827GitHub code search for direct mentions.
Google dork
"CVE-2026-57827" exploit -site:nvd.nist.govWrite-ups and news, NVD excluded.
Known PoCs on GitHub (6)
CVE-2026-578276 repos
killvxk/gitweeklyPython
收集各种有趣的github项目
zulloper/cve-pocPython
CVE POC repo 자동 수집기
shinthink/CVE-2026-57827Python
CVE-2026-57827 — RSFiles! Joomla Component Unauthenticated File Upload RCE. Split-controller upload bypass. CVSS 9.8 | CWE-434 | com_rsfiles < 1.17.12
Mohammad-008/rsfiles-CVE-2026-57827Python
Unauthenticated File Upload → RCE PoC for CVE-2026-57827 (RSFiles! Joomla < 1.17.12). Authorized security research use only.
HappyHackingSpace/vt-templatesPHP
jjkk123123/CVE-2026-57827Python
Joomla RSFiles 未授权文件上传CVE-2026-57827检测&利用脚本