CVE-2026-49048: Joomcoder Joomcck

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

The Joomla extension JoomCCK exposes a front-end controller task, that builds two SQL statements by directly concatenating a user-supplied request parameter into the query string without escaping or parameterisation.

Affected products

  • Joomcoder Joomcck: from 1.0, up to and including 6.4.0

Published 2026-06-28. Last modified 2026-06-30.