Security
Critical SQL injection fixed in Joomla JCTables
JoomCode has fixed a critical, unauthenticated SQL injection in its JCTables extension for Joomla. The flaw, tracked as CVE-2026-76570, affects every version before 1.21.1.
mySites.guru published the advisory, which reports that the vulnerability carries a CVSS 4.0 score of 10.0, the highest Critical rating. An attacker does not need an account or user interaction and can use the affected component to read and modify Joomla database records. The vulnerability class is SQL injection.
The write capability raises the risk beyond data exposure: the report says database changes could include administrator credentials, potentially enabling further compromise. VulnCheck found no evidence that the issue was being exploited in the wild, and it is not listed on CISA's Known Exploited Vulnerabilities catalogue as of the report.
- Update
JCTablesto1.21.1or later on every affected Joomla site. - If an immediate update is not possible, disable the component until it can be applied.
- Sites that ran an affected version should review administrator accounts and consider changing administrator passwords.
Originally reported by mySites.guru.