OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-100752

CRITICAL · CVSS 9.3 EPSS 0.28%

Source: NVD + CISA KEV + EPSS · Published 2026-09-28 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

The Joomla Extension from ordasoft.com is vulnerable to an unauthenticated SQL injection in the Real Estate Manager version prior to 6.7.9, allowing attackers to manipulate the ORDER BY clause in property-listing queries through the request-controlled order_field parameter. This critical vulnerability, with a CVSS score of 9.3, can lead to unauthorized data access and potential database compromise. Joomla administrators and developers using this extension should prioritize immediate remediation to mitigate risks associated with this exploit.

CVE
CVE-2026-100752
Severity
CRITICAL
CVSS
9.3
EPSS
0.28%

Original NVD Description

Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Real Estate Manager (Free) < 6.7.9 - site/realestatemanager.php builds the ORDER BY clause of three separate frontend property-listing queries (category browsing, search results, and the full property listing) from a request-controlled order_field parameter, concatenated directly into an unquoted SQL clause with no allow-list of real column names and no cast.