Live This site runs Joomla 6.1.2
JoomClub

News, security and craft for the Joomla ecosystem

Security

Six flaws found in three OrdaSoft Joomla extensions

Three OrdaSoft Joomla extensions contain unauthenticated SQL injection and reflected XSS vulnerabilities, with six CVEs assigned in total.

Research published by mySites.guru identifies the affected products as Real Estate Manager, Vehicle Manager and Book Library. Each has a public-facing SQL injection rated Critical at CVSS 9.3, as well as a reflected cross-site scripting issue rated Medium at 5.3.

  • Real Estate Manager: CVEs CVE-2026-100752 and CVE-2026-100753; affected through 6.7.8, fixed in 6.7.9.
  • Vehicle Manager: CVEs CVE-2026-101108 and CVE-2026-101109; affected through 6.5.7, fixed in 6.5.8.
  • Book Library: CVEs CVE-2026-101110 and CVE-2026-101111; versions below 6.4.6 are flagged, with 6.4.6 or a later release recommended.

The SQL injection flaws require no login. The XSS issues require someone to open a crafted link. The report does not state that either vulnerability type is being exploited. Administrators should identify these extensions and update them promptly. For Book Library, mySites.guru notes conflicting version information and advises installing the newest available release beyond 6.4.6. No OrdaSoft advisory was identified in the report.

Originally reported by mySites.guru.