Security
Six flaws found in three OrdaSoft Joomla extensions
Three OrdaSoft Joomla extensions contain unauthenticated SQL injection and reflected XSS vulnerabilities, with six CVEs assigned in total.
Research published by mySites.guru identifies the affected products as Real Estate Manager, Vehicle Manager and Book Library. Each has a public-facing SQL injection rated Critical at CVSS 9.3, as well as a reflected cross-site scripting issue rated Medium at 5.3.
Real Estate Manager: CVEsCVE-2026-100752andCVE-2026-100753; affected through 6.7.8, fixed in 6.7.9.Vehicle Manager: CVEsCVE-2026-101108andCVE-2026-101109; affected through 6.5.7, fixed in 6.5.8.Book Library: CVEsCVE-2026-101110andCVE-2026-101111; versions below 6.4.6 are flagged, with 6.4.6 or a later release recommended.
The SQL injection flaws require no login. The XSS issues require someone to open a crafted link. The report does not state that either vulnerability type is being exploited. Administrators should identify these extensions and update them promptly. For Book Library, mySites.guru notes conflicting version information and advises installing the newest available release beyond 6.4.6. No OrdaSoft advisory was identified in the report.
Originally reported by mySites.guru.