← Vulnerability feed

Vulnerability record · CVE-2011-4908 · published 12 February 2020

CVE-2011-4908: TinyBrowser Joomla plugin unrestricted file upload

Tiny · Tinybrowser

The TinyBrowser plugin for Joomla! before 1.5.13 exposes upload.php without restricting uploaded file types, allowing arbitrary file uploads. Because the endpoint is reachable over the network with no authentication or user interaction, an attacker can place executable content on the server. This is a critical-severity flaw in an end-of-life Joomla component.

9.8 CVSS 3.1 Critical EPSS 56% · top 1.0% CWE-434 · Unrestricted file upload
9.8CVSS 3.1 base score, v2 10.0
56%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

TinyBrowser plugin for Joomla! before 1.5.13 allows arbitrary file upload via upload.php.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityUnauthenticated remote arbitrary file upload with a CVSS of 9.8 and public exploit code makes full server compromise likely.

What it is

The TinyBrowser plugin for Joomla! before 1.5.13 exposes upload.php without restricting uploaded file types, allowing arbitrary file uploads. Because the endpoint is reachable over the network with no authentication or user interaction, an attacker can place executable content on the server. This is a critical-severity flaw in an end-of-life Joomla component.

Impact

An attacker can upload arbitrary files, including web shells, and execute them on the host, leading to full compromise of the Joomla site and potentially the underlying server.

Attack surface

Reached remotely over HTTP through the plugin's upload.php endpoint. The CVSS vector shows no privileges required and no user interaction, so the upload path is directly accessible to unauthenticated attackers.

Exploitation

Not listed in CISA KEV, but EPSS is 0.55769 (99th percentile) and public Exploit-DB and mailing-list references exist, indicating known exploit code and active interest.

What to do

  • Upgrade or remove the TinyBrowser plugin; Joomla! 1.5.13 or later is required per the advisory.
  • If the plugin cannot be removed, block or restrict access to upload.php at the web server or WAF.
  • Disable file uploads in the plugin and audit the upload directory for unexpected files.
  • Run the Joomla site with least privilege and keep the web root non-executable for uploaded content.
  • Monitor for and remove any web shells or unexpected executable files already present.

Detection

  • Review web server logs for POST requests to TinyBrowser upload.php, especially from unauthenticated clients.
  • Alert on new executable files (php, phtml, jsp, etc.) appearing in upload or media directories.
  • Scan the filesystem for web shells and compare against known-good file hashes.
  • Monitor outbound connections from the web server that may indicate post-exploitation activity.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2011-4908 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2011-4906Tinybrowser unrestricted file upload vulnerabilityTiny browser in TinyMCE 3.0 editor in Joomla! before 1.5.13 allows file upload and arbitrary PHP code execution.EPSS 9.6%10.0CVE-2026-56291Balbooa Forms Joomla extension unauthenticated arbitrary file upload RCEThe Balbooa Forms extension for Joomla before version 2.4.1 accepts file uploads without authentication and does not restrict file type, allowing exe…KEVEPSS 15%analysed10.0CVE-2026-48939iCagenda Joomla extension unrestricted file upload leads to PHP RCEThe iCagenda extension for Joomla fails to restrict file types in its file attachment feature, allowing arbitrary file uploads that result in PHP cod…KEVEPSS 20%analysed10.0CVE-2026-56290Joomla Page Builder CK unauthenticated file upload leads to RCEThe Joomla Page Builder CK extension before 3.6.0 allows unauthenticated arbitrary file uploads, letting an attacker place executable files on the se…KEVEPSS 31%analysed10.0CVE-2026-48908SP Page Builder for Joomla unauthenticated arbitrary file upload RCESP Page Builder for Joomla permits unauthenticated users to upload arbitrary files, which can lead to upload and execution of PHP code. The flaw is a…KEVEPSS 89%analysed9.8CVE-2024-7399Samsung MagicINFO 9 Server path traversal allows arbitrary file writeSamsung MagicINFO 9 Server before version 21.1050 contains a path traversal flaw (CWE-22) that also enables unrestricted file upload (CWE-434), letti…KEVEPSS 92%analysed7.2CVE-2025-2749Kentico Xperience path traversal and file upload lead to RCEKentico Xperience through 13.0.178 allows an authenticated Staging Sync Server user to upload arbitrary data to relative paths, enabling path travers…KEVEPSS 4.1%analysed7.2CVE-2024-7694ThreatSonar Anti-Ransomware unrestricted file upload enables command executionThreatSonar Anti-Ransomware from TeamT5 fails to properly validate the content of uploaded files (CWE-434). An attacker holding administrator privile…KEVEPSS 1.8%analysed

Source: NIST National Vulnerability Database (record CVE-2011-4908), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.