Security
OS CCK fixes critical Joomla upload flaw
OrdaSoft has fixed a critical, unauthenticated PHP upload vulnerability and a separate SQL injection in OS CCK for Joomla, but affected sites must install the patched release manually.
Research published by mySites.guru says OS CCK versions before 8.3.16 allowed visitors to upload files that could be executed as PHP. The flaw is tracked as CVE-2026-102427 and has a CVSS score of 10.0. A second, no-login SQL injection in public listing sort parameters is also fixed in 8.3.16, but has no CVE identifier or published severity rating.
There is no public report that either issue is being exploited, and the CVE is not listed in CISA's Known Exploited Vulnerabilities catalogue. However, the upload issue is remotely reachable, requires no account and can provide full control of the affected site.
- Install OrdaSoft
OS CCK 8.3.16or later manually; the vendor's update manifest continues to offer vulnerable8.3.14. - If an immediate update is not possible, disable the component. Check its upload directories for unexpected PHP files and investigate the site as potentially compromised if any are found.
Administrators should verify the installed version after updating rather than relying on Joomla's updater.
Originally reported by mySites.guru.