CVE-2026-101108
Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Vehicle Manager (Free) < 6.5.8
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Vehicle Manager (Free) < 6.5.8 - site/vehiclemanager.php reads the order_field and order_direction sort parameters at three separate anonymous-reachable frontend entry points (category listing, search, and the all-vehicles listing) through a sanitizing function that applies real escaping, but the value is then placed into an unquoted ORDER BY clause, where escaping has no protective effect.
| CWE | CWE-89 |
| Vendor | ordasoft.com |
| Product | vehicle manager (free) extension for joomla |
| Published | Sep 28, 2026 |
Stay Ahead of the Next One
Get instant alerts for ordasoft.com vehicle manager (free) extension for joomla
Be the first to know when new unknown vulnerabilities affecting ordasoft.com vehicle manager (free) extension for joomla are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
ordasoft.com / Vehicle Manager (Free) extension for Joomla
1.0.0-6.5.7
Credits
Ala Arfaoui