SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-65431

CRITICAL · CVSS 9.8 EPSS 0.38%

Source: NVD + CISA KEV + EPSS · Published 2026-07-23 · Last synced 2026-08-22

CyberRota Analysis

AI-Generated

The GeoIP extension for Joomla is vulnerable due to a Zipslip vulnerability that allows attackers to exploit unsafe file extractions from Geo IP database update archives, potentially leading to arbitrary file writes on the server. This critical flaw poses a significant risk of remote code execution and system compromise. Organizations using this extension should prioritize immediate remediation to safeguard against potential exploitation.

CVE
CVE-2026-65431
Severity
CRITICAL
CVSS
9.8
EPSS
0.38%

Original NVD Description

Joomla Extension - regularlabs.com - Zipslip in GeoIP extension - Geo IP database update archives have been broadly extracted without path validation, leading to unsafe file extractions.