CVE-2026-102428: Joomla Extension - ordasoft.com - Unauthenticated SQL injection in OrdaSoft Joomla CCK < 8.3.16
Published Oct 5, 2026
·Updated
Joomla Extension - ordasoft.com - Unauthenticated SQL injection in OrdaSoft Joomla CCK < 8.3.16 - The order column for records was user provided and not properly validated, leading to a SQL injection vector.
Affected Software
1 affected component
ordasoft Joomla CCK<8.3.16
Event History
Oct 5, 2026
CVE Published
via MITRE·04:06 PM
Data Sourced
via MITRE·04:06 PM
DescriptionWeakness
Frequently Asked Questions
1
Which deployments are affected?
OrdaSoft Joomla CCK versions earlier than 8.3.16 are affected. The issue is in handling a user-provided order column for records.
2
Does exploitation require authentication?
No. The vulnerability is described as unauthenticated, so an attacker does not need to log in before attempting to exploit the SQL injection vector.
3
What should be prioritized for remediation?
Upgrade OrdaSoft Joomla CCK to version 8.3.16 or later. The provided data does not identify a workaround or configuration-based mitigation.