CVE-2026-100752
Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Real Estate Manager (Free) < 6.7.9
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Real Estate Manager (Free) < 6.7.9 - site/realestatemanager.php builds the ORDER BY clause of three separate frontend property-listing queries (category browsing, search results, and the full property listing) from a request-controlled order_field parameter, concatenated directly into an unquoted SQL clause with no allow-list of real column names and no cast.
| CWE | CWE-89 |
| Vendor | ordasoft.com |
| Product | real estate manager (free) extension for joomla |
| Published | Sep 28, 2026 |
Stay Ahead of the Next One
Get instant alerts for ordasoft.com real estate manager (free) extension for joomla
Be the first to know when new unknown vulnerabilities affecting ordasoft.com real estate manager (free) extension for joomla are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
ordasoft.com / Real Estate Manager (Free) extension for Joomla
1.0.0-6.7.8
Credits
Ala Arfaoui