SQL Injection
22 articles tagged SQL Injection, newest first.

OS CCK 8.3.16 for Joomla Fixes a No-Login PHP Upload and an SQL Injection, but the Updater Still Offers 8.3.14
OS CCK for Joomla before 8.3.16 let anyone upload and run PHP (CVE-2026-102427, CVSS 10.0) and had a no-login SQL injection. The updater won't offer the fix.

JCTables for Joomla: Unauthenticated SQL Injection Fixed in 1.21.1
CVE-2026-76570 lets anyone read and rewrite a Joomla database through the JCTables extension without logging in. Scored 10.0 Critical, fixed in 1.21.1.

Three OrdaSoft Joomla Extensions Have Unauthenticated SQL Injections in Their Sort Order
Real Estate Manager, Vehicle Manager and Book Library for Joomla each have an SQL injection needing no login and a reflected XSS. Six CVEs and their fixes.

UP 6.1.0 fixes file read and code execution in the UP plugin for Joomla
Before UP 6.1.0, one anonymous request could read a Joomla site's configuration.php through the UP plugin, and any author could run PHP. We found it.

YouTube Gallery for Joomla: Unauthenticated SQL Injection Fixed in 5.7.3
CVE-2026-94130: an unauthenticated SQL injection in JoomlaBoat's YouTube Gallery for Joomla, scored 9.3 Critical. Every version below 5.7.3 is affected.

EasyStore 3.0.1 Fixes Seven Security Flaws mySites.guru Found in 3.0.0 on Release Day
Before EasyStore 3.0.1, any visitor could pull a Joomla shop customer's home address and phone number from their email. mySites.guru found it and six more.

Blind SQL Injection in Gridbox's Blog Author
Gridbox 2.20.3.1 fixes an unauthenticated blind SQL injection in the blog author parameter that can read a Joomla site's whole database. Update now.

OS Gallery 6.2.7 Fixes an Unauthenticated SQL Injection and Two Authenticated RCEs
OrdaSoft's OS Gallery below 6.2.7 has an SQL injection needing no login, two routes to remote code execution, and a second SQL injection. Update now.

Six more J2Store flaws fixed in 3.3.23, 4.0.23 and 4.1.8
J2Store 3.3.23, 4.0.23 and 4.1.8 fix six flaws mySites.guru reported, including an anonymous blind SQL injection that reads a Joomla shop's whole database.

SQL Injection and a Captcha Bypass in the SP Page Builder Joomla Extension, found by mySites.guru
mySites.guru found an Author-level SQL injection and an unauthenticated captcha bypass in the SP Page Builder Joomla extension, both fixed in 6.9.1.

Unauthenticated SQL Injection in SP Property Finder found by mySites.guru
mySites.guru found an unauthenticated blind SQL injection in JoomShaper's SP Property Finder. Any visitor could read the database. Fixed in 4.1.4.

DPCalendar 10.12.0 fixes an SQL injection and an XSS
Digital Peak fixed a blind SQL injection and a stored XSS in DPCalendar 10.12.0, backported to 8.19.5 for Joomla 3. Both need a logged-in user.

Fabrik 4.7.2 for Joomla: A Long List of Security Fixes
Fabrik 4.7.2 for the Joomla extension closes a long list of unauthenticated vulnerabilities, most of them found and reported by mySites.guru. Update now.

A CVSS 10.0 Unauthenticated Upload in YOOtheme ZOO, Fixed in 4.1.66
YOOtheme ZOO (com_zoo) up to 4.1.63 had an unauthenticated file upload RCE scored CVSS 10.0, plus a SQL injection, fixed in 4.1.64. Install 4.1.66.

iCagenda 4.0.12 fixes an unauthenticated SQL injection
CVE-2026-67365 is an unauthenticated SQL injection in the iCagenda Calendar module for Joomla, scored 9.2 Critical. Fixed in 4.0.12.

Phoca Cart 5.2.4, 6.1.7 and 4.0.13 fix a front-end SQL injection
Phoca Cart 5.2.4, 6.1.7 and 4.0.13 patch an unauthenticated SQL injection in the Joomla extension's product filter. Joomla 5 on 6.x isn't offered it.

Pre-Authentication SQL Injection and Mail Relay in SP Page Builder found by mySites.guru
mySites.guru found four vulnerabilities in SP Page Builder for Joomla: a SQL injection and a mail relay, fixed in 6.7.1. A fifth was still there until 6.8.0.

Exposed Customer Invoices, Order Forgery and SQL Injection in EasyStore for Joomla found by mySites.guru
Before EasyStore 2.0.2, any logged-in customer could read every other customer's invoice by editing one URL. mySites.guru found this and two more flaws.

Unauthenticated SQL Injection in Quix Page Builder found by mySites.guru
mySites.guru found and reported CVE-2026-58078, an unauthenticated SQL injection in Quix Page Builder for Joomla. Fixed in 6.2.1; update to 6.2.2.

Unauthenticated SQL Injection in EDocman found by mySites.guru
mySites.guru found an unauthenticated SQL injection in EDocman for Joomla that let anyone read the whole database. Fixed in 3.9.0 - update now.

Unauthenticated SQL Injection in DPCalendar found by mySites.guru
mySites.guru found and reported an unauthenticated SQL injection in the DPCalendar Joomla extension's public events feed. Fixed in 10.11.2 and 8.19.4.

Unauthenticated SQL Injection in AcyMailing found by mySites.guru
mySites.guru found and reported CVE-2026-56292, an unauthenticated SQL injection in AcyMailing for Joomla and WordPress. Update to 10.11.1 now.