CVE-2026-101111: Ordasoft Book Library
Medium severity, CVSS 6.1. EPSS: 0.1% chance of exploitation in the next 30 days.
Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Book Library (Free) < 6.4.6 - The public book-detail page template, site/views/view_book/tmpl/default.php, echoes the raw title request parameter directly into a double-quoted HTML attribute with no escaping function of any kind (echo $_REQUEST["title"];). A value containing a double quote closes the attribute early and allows arbitrary HTML/JavaScript to follow.
Affected products
- Ordasoft Book Library: from 1.0.0, before 6.4.6 (fixed in 6.4.6)
Published 2026-09-28. Last modified 2026-10-01.