CVE-2026-49048: Joomcoder Joomcck
Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.
The Joomla extension JoomCCK exposes a front-end controller task, that builds two SQL statements by directly concatenating a user-supplied request parameter into the query string without escaping or parameterisation.
Affected products
- Joomcoder Joomcck: from 1.0, up to and including 6.4.0
Published 2026-06-28. Last modified 2026-06-30.