πŸ” CVE Alert

CVE-2026-102781

UNKNOWN 0.0

Joomla Extension - ordasoft.com - Unauthenticated Destructive CRUD in OrdaSoft Touch Slider < 5.4.6

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Joomla Extension - ordasoft.com - Unauthenticated Destructive CRUD in OrdaSoft Touch Slider < 5.4.6 - modOsTouchSliderHelper::getAjax(), wired through Joomla’s core com_ajax dispatcher, is the single handler behind every data-management operation this module exposes. No call to JFactory::getUser(), authorise(), or a CSRF token check exists anywhere in the handler. Two confirmed impact paths: an unauthenticated GET deletes any slider image by guessable sequential IDs, and an unauthenticated multipart upload with a zip file renames and replaces the entire #__os_touch_slider/#__os_touch_slider_text tables site-wide with attacker-supplied content, with no task parameter even required for the second path.

CWE CWE-284
Vendor ordasoft.com
Product touch slider extension for joomla
Published Oct 7, 2026
Stay Ahead of the Next One

Get instant alerts for ordasoft.com touch slider extension for joomla

Be the first to know when new unknown vulnerabilities affecting ordasoft.com touch slider extension for joomla are published β€” delivered to Slack, Telegram or Discord.

Get Free Alerts β†’ Free Β· No credit card Β· 60 sec setup

Affected Versions

ordasoft.com / Touch Slider extension for Joomla
1.0.0-5.4.5

References

NVD β†— CVE.org β†— EPSS Data β†—
ordasoft.com: https://www.ordasoft.com/