OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-101108

CRITICAL · CVSS 9.3 EPSS 0.28%

Source: NVD + CISA KEV + EPSS · Published 2026-09-28 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

The Vehicle Manager extension for Joomla, versions prior to 6.5.8, is vulnerable to unauthenticated SQL injection due to improper handling of the order_field and order_direction parameters in the ORDER BY clause. This flaw allows attackers to manipulate database queries, potentially leading to data exposure or corruption. Organizations using this extension should prioritize immediate updates to mitigate the risk of exploitation.

CVE
CVE-2026-101108
Severity
CRITICAL
CVSS
9.3
EPSS
0.28%

Original NVD Description

Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Vehicle Manager (Free) < 6.5.8 - site/vehiclemanager.php reads the order_field and order_direction sort parameters at three separate anonymous-reachable frontend entry points (category listing, search, and the all-vehicles listing) through a sanitizing function that applies real escaping, but the value is then placed into an unquoted ORDER BY clause, where escaping has no protective effect.