Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
9.3
CVE-2026-102428
- EPSS 0.28%
- Veröffentlicht 05.10.2026 16:06:20
- Zuletzt bearbeitet 06.10.2026 15:05:34
Joomla Extension - ordasoft.com - Unauthenticated SQL injection in OrdaSoft Joomla CCK < 8.3.16 - The order column for records was user provided and not properly validated, leading to a SQL injection vector.
- EPSS 0.79%
- Veröffentlicht 30.09.2026 15:14:49
- Zuletzt bearbeitet 01.10.2026 13:46:23
Joomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in OrdaSoft Joomla CCK < 8.3.16 - site/uploader.php is reached through the component’s normal frontend routing (task=getContent), a task with no authentication or ACL check anywh...
1