Joomla Critical · CVSS 9.2 CVE-2026-67285 August 12, 2026

Joomla: file inclusion (LFI/RFI)

Joomla

File inclusion (LFI/RFI) in the Joomla component. Threat level: Critical (CVSS 9.2).

Worried this flaw is on your site? Check it for free in under a minute, or have us fix and secure it right away.

Who is affected

This vulnerability affects: Joomla. If you use this component on your site, check the version and update it as soon as possible.

How dangerous

Rating: Critical, CVSS 9.2 out of 10. Critical flaws are often exploited en masse within hours of disclosure.

What this flaw is

File inclusion (LFI/RFI) lets an attacker force the site to load a file outside its intended scope, local (e.g. configuration) or remote.

It can expose sensitive configuration files (database credentials) and is often the first step in a chain leading to code execution.

Score breakdown (CVSS vector)

What the CVSS 9.2 rating means in practice:

  • The attack can be carried out remotely, over the internet.
  • No login or account required.
  • Requires no action from the victim.

Weakness class: CWE-22.

What to do

  • Update the vulnerable component (Joomla) to the latest version.
  • If a patch is not out yet, temporarily disable the vulnerable element.
  • Check whether the site has already been attacked: unusual files, new administrator accounts, redirects.
  • Make a backup before you start making changes.
Do not guess, check

Does this flaw affect your site?

We will run a free audit: we check versions, plugins, and configuration, and tell you plainly whether you are safe.

Request a free audit →