๐Ÿ” CVE Alert

CVE-2026-101108

UNKNOWN 0.0

Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Vehicle Manager (Free) < 6.5.8

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Vehicle Manager (Free) < 6.5.8 - site/vehiclemanager.php reads the order_field and order_direction sort parameters at three separate anonymous-reachable frontend entry points (category listing, search, and the all-vehicles listing) through a sanitizing function that applies real escaping, but the value is then placed into an unquoted ORDER BY clause, where escaping has no protective effect.

CWE CWE-89
Vendor ordasoft.com
Product vehicle manager (free) extension for joomla
Published Sep 28, 2026
Stay Ahead of the Next One

Get instant alerts for ordasoft.com vehicle manager (free) extension for joomla

Be the first to know when new unknown vulnerabilities affecting ordasoft.com vehicle manager (free) extension for joomla are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

ordasoft.com / Vehicle Manager (Free) extension for Joomla
1.0.0-6.5.7

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
ordasoft.com: https://www.ordasoft.com/

Credits

Ala Arfaoui