CVE-2026-78080: Joomla Extension - feenders.de - Unauthenticated SQL injection in JooDatabase Lite < 5.1.0
Published Sep 3, 2026
·Updated
Joomla Extension - feenders.de - Unauthenticated SQL injection in JooDatabase Lite < 5.1.0 - The cid parameter is used in queries without validation, allowing SQLi vectors.
Affected Software
1 affected component
JooDatabase Lite<5.1.0
Event History
Sep 3, 2026
CVE Published
via MITRE·12:24 PM
Data Sourced
via MITRE·12:24 PM
DescriptionWeakness
Frequently Asked Questions
1
What input is vulnerable to injection?
The cid parameter is used in database queries without validation, allowing SQL injection vectors.
2
Do attackers need to authenticate first?
No. The issue is described as unauthenticated, so an attacker does not need an authenticated Joomla or extension account to exploit the vulnerable parameter.
3
Which versions are affected?
JooDatabase Lite versions earlier than 5.1.0 are affected.