CVE-2026-97160: Joomla Extension - lomart.fr - Authenticated, privileged PHP command injection in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29
Published Sep 26, 2026
·Updated
Joomla Extension - lomart.fr - Authenticated, privileged PHP command injection in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29
Affected Software
1 affected component
lomart.fr UP plugin>=5.0.0<=5.2.0, >=6.0.0<=6.0.29
Event History
Sep 26, 2026
CVE Published
via MITRE·02:30 PM
Data Sourced
via MITRE·02:30 PM
DescriptionWeakness
Frequently Asked Questions
1
Which accounts present an exploitation risk?
Exploitation requires an authenticated, privileged account. Review access to privileged Joomla accounts on installations using the affected UP plugin versions.