CVE-2026-49048: Joomla Extension - joomcoder.com - Unauthenticated SQL Injection in JoomCCK extension for Joomla < 6.4.1
Published Jun 28, 2026
·Updated
The Joomla extension JoomCCK exposes a front-end controller task, that builds two SQL statements by directly concatenating a user-supplied request parameter into the query string without escaping or parameterisation.
Affected Software
2 affected components
joomcoder JoomCCK (Joomla extension)<6.4.1
joomcoder Joomcck Joomla\!>=1.0<=6.4.0
Event History
Jun 28, 2026
CVE Published
via MITRE·06:37 PM
Data Sourced
via MITRE·06:37 PM
DescriptionWeakness
Data Sourced
via NVD·07:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-49048?
CVE-2026-49048 has a risk rating of 84, indicating a high severity SQL Injection vulnerability.
2
How do I fix CVE-2026-49048?
To fix CVE-2026-49048, update the JoomCCK extension to version 6.4.1 or higher.
3
What kind of vulnerability is CVE-2026-49048?
CVE-2026-49048 is classified as an Unauthenticated SQL Injection vulnerability.
4
What versions of JoomCCK are affected by CVE-2026-49048?
CVE-2026-49048 affects all versions of the JoomCCK extension for Joomla prior to 6.4.1.
5
Can CVE-2026-49048 be exploited remotely?
Yes, CVE-2026-49048 can be exploited remotely due to unescaped user-supplied parameters in SQL queries.