CVE-2026-100752: Ordasoft.com Real Estate Manager Free Extension For Joomla
Critical severity, CVSS 9.3. EPSS: 0.3% chance of exploitation in the next 30 days.
Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Real Estate Manager (Free) < 6.7.9 - site/realestatemanager.php builds the ORDER BY clause of three separate frontend property-listing queries (category browsing, search results, and the full property listing) from a request-controlled order_field parameter, concatenated directly into an unquoted SQL clause with no allow-list of real column names and no cast.
Affected products
- Ordasoft.com Real Estate Manager Free Extension For Joomla: version 1.0.0-6.7.8 only
Published 2026-09-28. Last modified 2026-09-30.