Joomla Extension 4.1.4 - PHP Object injection

cve CVE-2026-48909 1 source, 1 claim · Watch

What each source says

PropertySourceSaidMeans here
Author
author
Exploit-DBAmin İsayev
receipt
Source
Exploit-DB
Its words
Amin İsayev
Read by
field:author
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-04 12:06 UTC
Original
open at the source
What the source handed over
{
  "aliases": "",
  "application_url": "",
  "author": "Amin İsayev",
  "codes": "CVE-2026-48909",
  "date_added": "2026-07-06",
  "date_published": "2026-07-06",
  "date_updated": "2026-07-06",
  "description": "Joomla Extension 4.1.4 - PHP Object injection",
  "file": "exploits/php/webapps/52617.txt",
  "id": "52617",
  "platform": "php",
  "port": "",
  "screenshot_url": "",
  "source_url": "",
  "tags": "",
  "type": "webapps",
  "verified": "0"
}
—
Platform
platform
Exploit-DBphp
receipt
Source
Exploit-DB
Its words
php
Read by
field:platform
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-04 12:06 UTC
Original
open at the source
What the source handed over
{
  "aliases": "",
  "application_url": "",
  "author": "Amin İsayev",
  "codes": "CVE-2026-48909",
  "date_added": "2026-07-06",
  "date_published": "2026-07-06",
  "date_updated": "2026-07-06",
  "description": "Joomla Extension 4.1.4 - PHP Object injection",
  "file": "exploits/php/webapps/52617.txt",
  "id": "52617",
  "platform": "php",
  "port": "",
  "screenshot_url": "",
  "source_url": "",
  "tags": "",
  "type": "webapps",
  "verified": "0"
}
—
Type
type
Exploit-DBwebapps
receipt
Source
Exploit-DB
Its words
webapps
Read by
field:type
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-04 12:06 UTC
Original
open at the source
What the source handed over
{
  "aliases": "",
  "application_url": "",
  "author": "Amin İsayev",
  "codes": "CVE-2026-48909",
  "date_added": "2026-07-06",
  "date_published": "2026-07-06",
  "date_updated": "2026-07-06",
  "description": "Joomla Extension 4.1.4 - PHP Object injection",
  "file": "exploits/php/webapps/52617.txt",
  "id": "52617",
  "platform": "php",
  "port": "",
  "screenshot_url": "",
  "source_url": "",
  "tags": "",
  "type": "webapps",
  "verified": "0"
}
—
Verified
verified
Exploit-DBfalse
receipt
Source
Exploit-DB
Its words
0
Read by
field:verified
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-04 12:06 UTC
Original
open at the source
What the source handed over
{
  "aliases": "",
  "application_url": "",
  "author": "Amin İsayev",
  "codes": "CVE-2026-48909",
  "date_added": "2026-07-06",
  "date_published": "2026-07-06",
  "date_updated": "2026-07-06",
  "description": "Joomla Extension 4.1.4 - PHP Object injection",
  "file": "exploits/php/webapps/52617.txt",
  "id": "52617",
  "platform": "php",
  "port": "",
  "screenshot_url": "",
  "source_url": "",
  "tags": "",
  "type": "webapps",
  "verified": "0"
}
—

exploit

Joomla Extension 4.1.4 - PHP Object injection
zetlyn/cve-exploitdb · 2026-07-06
author Amin İsayev platform php type webapps verified false source