OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-102428

CRITICAL · CVSS 9.3

Source: NVD + CISA KEV + EPSS · Published 2026-10-05 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

The OrdaSoft Joomla CCK extension versions prior to 8.3.16 are vulnerable to an unauthenticated SQL injection due to insufficient validation of the user-provided order column for records. This critical vulnerability allows attackers to execute arbitrary SQL queries, potentially compromising the database and exposing sensitive information. Joomla site administrators and users of the affected extension should prioritize immediate updates to mitigate the risk.

CVE
CVE-2026-102428
Severity
CRITICAL
CVSS
9.3
EPSS
N/A

Original NVD Description

Joomla Extension - ordasoft.com - Unauthenticated SQL injection in OrdaSoft Joomla CCK < 8.3.16 - The order column for records was user provided and not properly validated, leading to a SQL injection vector.