CVE-2026-102428: Ordasoft.com Ordasoft Joomla Cck

Critical severity, CVSS 9.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Joomla Extension - ordasoft.com - Unauthenticated SQL injection in OrdaSoft Joomla CCK < 8.3.16 - The order column for records was user provided and not properly validated, leading to a SQL injection vector.

Affected products

Published 2026-10-05. Last modified 2026-10-06.