CVE-2026-101109: Ordasoft.com Vehicle Manager Free Extension For Joomla

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Vehicle Manager (Free) < 6.5.8 - The public vehicle-detail page (task=view) echoes the title request parameter directly into a double-quoted HTML attribute with no output encoding of any kind. A double-quote character in the parameter closes the attribute, allowing arbitrary markup, including a <script> tag, to be injected into the page.

Affected products

  • Ordasoft.com Vehicle Manager Free Extension For Joomla: version 1.0.0-6.5.7 only

Published 2026-09-28. Last modified 2026-09-30.