Four CMS Plugins, Four Vendors, the Same Unrestricted Upload Bug in Three Days
Four Joomla extensions from unrelated developers had unauthenticated file upload vulnerabilities confirmed exploited within a three-day window in July 2026, every one scoring CVSS 9.8.