Threat intelligence dashboard
CVE-2026-101111medium

Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Book Library (Free) < 6.4.6

Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Book Library (Free) < 6.4.6 - The public book-detail page template, site/views/view_book/tmpl/default.php, echoes the raw title request parameter directly into a double-quoted HTML attribute with no escaping function of any kind (echo $_REQUEST["title"];). A value containing a double quote closes the attribute early and allows arbitrary HTML/JavaScript to follow.

Risk score

5.3

CVSS 4.0

Vendor
ordasoft.com
Product
Book Library (Free) extension for Joomla
CWE
CWE-79
Published
Sep 28, 2026
Updated
Sep 28, 2026
CISA KEV
Not flagged

Affected products and versions

Book Library (Free) extension for Joomla

ordasoft.com

Version / rangeStatusType
1.0.0-6.4.6affected—

Technical metrics

5.3

CVSS 4.0

Severity
medium
Source
Joomla
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N