CVE-2026-78072: Joomla Extension - Jefferson49 - Unauthenticated blind SQLi in Sexy Polling Reloaded < 5.6.1
Published Aug 28, 2026
·Updated
Joomla Extension - Jefferson49 - Unauthenticated blind SQLi in Sexy Polling Reloaded < 5.6.1
Affected Software
1 affected component
Joomla Extension - Jefferson49 - Sexy Polling Reloaded<5.6.1
Event History
Aug 28, 2026
CVE Published
via MITRE·07:41 AM
Data Sourced
via MITRE·07:41 AM
DescriptionWeakness
Frequently Asked Questions
1
Which installations should be prioritized for remediation?
Installations using Sexy Polling Reloaded versions earlier than 5.6.1 should be prioritized.
2
Does an attacker need an account to exploit this issue?
No. The issue is described as unauthenticated, so exploitation does not require prior authentication.