Ordasoft

Joomla Cck

2 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.28%
  • Veröffentlicht 05.10.2026 16:06:20
  • Zuletzt bearbeitet 06.10.2026 15:05:34

Joomla Extension - ordasoft.com - Unauthenticated SQL injection in OrdaSoft Joomla CCK < 8.3.16 - The order column for records was user provided and not properly validated, leading to a SQL injection vector.

  • EPSS 0.79%
  • Veröffentlicht 30.09.2026 15:14:49
  • Zuletzt bearbeitet 01.10.2026 13:46:23

Joomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in OrdaSoft Joomla CCK < 8.3.16 - site/uploader.php is reached through the component’s normal frontend routing (task=getContent), a task with no authentication or ACL check anywh...