Threat intelligence dashboard
CVE-2026-101108critical

Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Vehicle Manager (Free) < 6.5.8

Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Vehicle Manager (Free) < 6.5.8 - site/vehiclemanager.php reads the order_field and order_direction sort parameters at three separate anonymous-reachable frontend entry points (category listing, search, and the all-vehicles listing) through a sanitizing function that applies real escaping, but the value is then placed into an unquoted ORDER BY clause, where escaping has no protective effect.

Risk score

9.3

CVSS 4.0

Vendor
ordasoft.com
Product
Vehicle Manager (Free) extension for Joomla
CWE
CWE-89
Published
Sep 28, 2026
Updated
Sep 28, 2026
CISA KEV
Not flagged

Affected products and versions

Vehicle Manager (Free) extension for Joomla

ordasoft.com

Version / rangeStatusType
1.0.0-6.5.7affected—

Technical metrics

9.3

CVSS 4.0

Severity
critical
Source
Joomla
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N