CVE-2026-102428

Joomla Extension - ordasoft.com - Unauthenticated SQL injection in OrdaSoft Joomla CCK < 8.3.16 - The order column for records was user provided and not properly validated, leading to a SQL injection vector.

  • Published Oct 5, 2026
  • CVSS 9.3 critical

Affected software

CVE-2026-102428 at the National Vulnerability Database