← Vulnerability feed

Vulnerability record · CVE-2013-5576 · published 9 October 2013

CVE-2013-5576: Joomla media manager file upload restriction bypass via trailing dot filename

Joomla · Joomla\!

The media manager in Joomla! 2.5.x before 2.5.14 and 3.x before 3.1.5 fails to properly validate uploaded filenames, allowing a filename with a trailing dot to bypass the dangerous-extension blocklist. This lets an attacker upload executable files to the web server, which can lead to remote code execution and full site compromise.

6.8 CVSS 2.0 Medium EPSS 48% · top 1.2% CWE-20 · Improper input validation
6.8CVSS 2.0 base score
48%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
18References, 4 tagged exploit
16 Jun 2026Last modified by NVD

Description

administrator/components/com_media/helpers/media.php in the media manager in Joomla! 2.5.x before 2.5.14 and 3.x before 3.1.5 allows remote authenticated users or remote attackers to bypass intended access restrictions and upload files with dangerous extensions via a filename with a trailing . (dot), as exploited in the wild in August 2013.

AV:N/AC:M/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

high priorityThe flaw allows unauthenticated remote file upload leading to code execution, was exploited in the wild, and has a high EPSS score despite a medium CVSS base score.

What it is

The media manager in Joomla! 2.5.x before 2.5.14 and 3.x before 3.1.5 fails to properly validate uploaded filenames, allowing a filename with a trailing dot to bypass the dangerous-extension blocklist. This lets an attacker upload executable files to the web server, which can lead to remote code execution and full site compromise.

Impact

An attacker can upload and execute arbitrary files on the Joomla server, gaining the ability to run code with the web server's privileges and take over the site.

Attack surface

Reached remotely over the network through the media manager upload functionality; the CVSS vector indicates no authentication is required, though the description also notes remote authenticated users can exploit it. No user interaction is needed.

Exploitation

Exploited in the wild in August 2013, with a public Exploit-DB entry and patch commits available; not listed in CISA KEV, but EPSS probability is 0.48191 (98.8th percentile).

What to do

  • Upgrade Joomla! to 2.5.14 or 3.1.5 (or later) immediately.
  • If immediate upgrade is not possible, restrict or disable the media manager upload feature for untrusted users.
  • Enforce server-side file extension allowlisting and reject filenames with trailing dots or other malformed extensions.
  • Review and remove any unexpected executable files in Joomla upload directories.
  • Apply the referenced Joomla patch commits if maintaining a custom build.

Detection

  • Monitor web server logs for upload requests to com_media with filenames ending in a dot or containing suspicious extensions.
  • Scan Joomla upload directories for newly created executable files (e.g., .php, .phtml, .php5) or files with trailing dots.
  • Alert on outbound connections or process creation from the web server user that may indicate uploaded shell execution.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2013-5576 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2016-10033PHPMailer isMail mailSend argument injection enables remote code executionPHPMailer before 5.2.18 fails to properly sanitize the Sender property in the mailSend function of the isMail transport, allowing a crafted backslash…KEVEPSS 100%analysed5.3CVE-2023-23752Joomla! webservice endpoints improper access checkJoomla! 4.0.0 through 4.2.7 contains an improper access check that allows unauthenticated access to webservice endpoints. Because the endpoints can e…KEVEPSS 100%analysed9.8CVE-2026-48902Joomla\! cleartext transmission vulnerabilityThe password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set.EPSS 0.33%9.8CVE-2025-25226Joomla\! sql injection vulnerabilityImproper handling of identifiers lead to a SQL injection vulnerability in the quoteNameStr method of the database package. Please note: the affected …EPSS 0.47%9.8CVE-2022-23795Joomla\! improper authentication vulnerabilityAn issue was discovered in Joomla! 2.5.0 through 3.10.6 & 4.0.0 through 4.1.0. A user row was not bound to a specific authentication mechanism which …EPSS 1.1%9.8CVE-2022-23797Joomla\! sql injection vulnerabilityAn issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Inadequate filtering on the selected Ids on an request could resulted …EPSS 1.1%9.8CVE-2022-23799Joomla\! vulnerabilityAn issue was discovered in Joomla! 4.0.0 through 4.1.0. Under specific circumstances, JInput pollutes method-specific input bags with $_REQUEST data.EPSS 1.2%9.8CVE-2010-1433Joomla\! unrestricted file upload vulnerabilityJoomla! Core is prone to a vulnerability that lets attackers upload arbitrary files because the application fails to properly verify user-supplied in…EPSS 1.1%

Source: NIST National Vulnerability Database (record CVE-2013-5576), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.