All verified exploits

CVE-2026-21628 Unauthenticated RCE via Astroid Framework AJAX Handlers

Deterministic critical Joomla Added cve-verified-cve-2026-21628

Detects Joomla installs running the Astroid Template Framework at version 3.3.10 or earlier. The framework's system plugin exposes admin AJAX endpoints without authentication — it checks CSRF tokens but never verifies the caller is an admin. An attacker grabs a token from the public login page, then uses the media upload handler to upload a PHP web shell. In the wild, attackers are installing persistent backdoor plugins (plg_system_blpayload). Update to Astroid Framework 3.3.11 or later.

Is your app exploitable through CVE-2026-21628?

Scan your domain free