CVE 4.8 MEDIUM

Extension – stackideas.com – Lack of mime type validation in EasyDiscuss component 1.0.0-5.0.15 for Joomla_CVE-2026-21625

4.8 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:L

Description

User provided uploads to the Easy Discuss component for Joomla aren't properly validated. Uploads are purely checked by file extensions, no mime type checks are happening.

Basic Information

ID CVE-2026-21625
Source Joomla
Published Jan 16, 2026 at 15:06

Affected Product

Vendor Stackideas.com
Product EasyDiscuss extension for Joomla
Version 1.0.0-5.0.15
Affected Versions Stackideas.com EasyDiscuss extension for Joomla 1.0.0-5.0.15

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.