Skip to main content
mySites.guru
J!Awards 2026mySites.guru is shortlisted for Your Favourite Tool in Your Joomla WorkflowVote by 11 OctoberHow to vote

SQL Injection

22 articles tagged SQL Injection, newest first.

OS CCK 8.3.16 for Joomla Fixes a No-Login PHP Upload and an SQL Injection, but the Updater Still Offers 8.3.14

OS CCK 8.3.16 for Joomla Fixes a No-Login PHP Upload and an SQL Injection, but the Updater Still Offers 8.3.14

OS CCK for Joomla before 8.3.16 let anyone upload and run PHP (CVE-2026-102427, CVSS 10.0) and had a no-login SQL injection. The updater won't offer the fix.

JCTables for Joomla: Unauthenticated SQL Injection Fixed in 1.21.1

JCTables for Joomla: Unauthenticated SQL Injection Fixed in 1.21.1

CVE-2026-76570 lets anyone read and rewrite a Joomla database through the JCTables extension without logging in. Scored 10.0 Critical, fixed in 1.21.1.

Three OrdaSoft Joomla Extensions Have Unauthenticated SQL Injections in Their Sort Order

Three OrdaSoft Joomla Extensions Have Unauthenticated SQL Injections in Their Sort Order

Real Estate Manager, Vehicle Manager and Book Library for Joomla each have an SQL injection needing no login and a reflected XSS. Six CVEs and their fixes.

UP 6.1.0 fixes file read and code execution in the UP plugin for Joomla

UP 6.1.0 fixes file read and code execution in the UP plugin for Joomla

Before UP 6.1.0, one anonymous request could read a Joomla site's configuration.php through the UP plugin, and any author could run PHP. We found it.

YouTube Gallery for Joomla: Unauthenticated SQL Injection Fixed in 5.7.3

YouTube Gallery for Joomla: Unauthenticated SQL Injection Fixed in 5.7.3

CVE-2026-94130: an unauthenticated SQL injection in JoomlaBoat's YouTube Gallery for Joomla, scored 9.3 Critical. Every version below 5.7.3 is affected.

EasyStore 3.0.1 Fixes Seven Security Flaws mySites.guru Found in 3.0.0 on Release Day

EasyStore 3.0.1 Fixes Seven Security Flaws mySites.guru Found in 3.0.0 on Release Day

Before EasyStore 3.0.1, any visitor could pull a Joomla shop customer's home address and phone number from their email. mySites.guru found it and six more.

Blind SQL Injection in Gridbox's Blog Author

Blind SQL Injection in Gridbox's Blog Author

Gridbox 2.20.3.1 fixes an unauthenticated blind SQL injection in the blog author parameter that can read a Joomla site's whole database. Update now.

OS Gallery 6.2.7 Fixes an Unauthenticated SQL Injection and Two Authenticated RCEs

OS Gallery 6.2.7 Fixes an Unauthenticated SQL Injection and Two Authenticated RCEs

OrdaSoft's OS Gallery below 6.2.7 has an SQL injection needing no login, two routes to remote code execution, and a second SQL injection. Update now.

Six more J2Store flaws fixed in 3.3.23, 4.0.23 and 4.1.8

Six more J2Store flaws fixed in 3.3.23, 4.0.23 and 4.1.8

J2Store 3.3.23, 4.0.23 and 4.1.8 fix six flaws mySites.guru reported, including an anonymous blind SQL injection that reads a Joomla shop's whole database.

SQL Injection and a Captcha Bypass in the SP Page Builder Joomla Extension, found by mySites.guru

SQL Injection and a Captcha Bypass in the SP Page Builder Joomla Extension, found by mySites.guru

mySites.guru found an Author-level SQL injection and an unauthenticated captcha bypass in the SP Page Builder Joomla extension, both fixed in 6.9.1.

Unauthenticated SQL Injection in SP Property Finder found by mySites.guru

Unauthenticated SQL Injection in SP Property Finder found by mySites.guru

mySites.guru found an unauthenticated blind SQL injection in JoomShaper's SP Property Finder. Any visitor could read the database. Fixed in 4.1.4.

DPCalendar 10.12.0 fixes an SQL injection and an XSS

DPCalendar 10.12.0 fixes an SQL injection and an XSS

Digital Peak fixed a blind SQL injection and a stored XSS in DPCalendar 10.12.0, backported to 8.19.5 for Joomla 3. Both need a logged-in user.

Fabrik 4.7.2 for Joomla: A Long List of Security Fixes

Fabrik 4.7.2 for Joomla: A Long List of Security Fixes

Fabrik 4.7.2 for the Joomla extension closes a long list of unauthenticated vulnerabilities, most of them found and reported by mySites.guru. Update now.

A CVSS 10.0 Unauthenticated Upload in YOOtheme ZOO, Fixed in 4.1.66

A CVSS 10.0 Unauthenticated Upload in YOOtheme ZOO, Fixed in 4.1.66

YOOtheme ZOO (com_zoo) up to 4.1.63 had an unauthenticated file upload RCE scored CVSS 10.0, plus a SQL injection, fixed in 4.1.64. Install 4.1.66.

iCagenda 4.0.12 fixes an unauthenticated SQL injection

iCagenda 4.0.12 fixes an unauthenticated SQL injection

CVE-2026-67365 is an unauthenticated SQL injection in the iCagenda Calendar module for Joomla, scored 9.2 Critical. Fixed in 4.0.12.

Phoca Cart 5.2.4, 6.1.7 and 4.0.13 fix a front-end SQL injection

Phoca Cart 5.2.4, 6.1.7 and 4.0.13 fix a front-end SQL injection

Phoca Cart 5.2.4, 6.1.7 and 4.0.13 patch an unauthenticated SQL injection in the Joomla extension's product filter. Joomla 5 on 6.x isn't offered it.

Pre-Authentication SQL Injection and Mail Relay in SP Page Builder found by mySites.guru

Pre-Authentication SQL Injection and Mail Relay in SP Page Builder found by mySites.guru

mySites.guru found four vulnerabilities in SP Page Builder for Joomla: a SQL injection and a mail relay, fixed in 6.7.1. A fifth was still there until 6.8.0.

Exposed Customer Invoices, Order Forgery and SQL Injection in EasyStore for Joomla found by mySites.guru

Exposed Customer Invoices, Order Forgery and SQL Injection in EasyStore for Joomla found by mySites.guru

Before EasyStore 2.0.2, any logged-in customer could read every other customer's invoice by editing one URL. mySites.guru found this and two more flaws.

Unauthenticated SQL Injection in Quix Page Builder found by mySites.guru

Unauthenticated SQL Injection in Quix Page Builder found by mySites.guru

mySites.guru found and reported CVE-2026-58078, an unauthenticated SQL injection in Quix Page Builder for Joomla. Fixed in 6.2.1; update to 6.2.2.

Unauthenticated SQL Injection in EDocman found by mySites.guru

Unauthenticated SQL Injection in EDocman found by mySites.guru

mySites.guru found an unauthenticated SQL injection in EDocman for Joomla that let anyone read the whole database. Fixed in 3.9.0 - update now.

Unauthenticated SQL Injection in DPCalendar found by mySites.guru

Unauthenticated SQL Injection in DPCalendar found by mySites.guru

mySites.guru found and reported an unauthenticated SQL injection in the DPCalendar Joomla extension's public events feed. Fixed in 10.11.2 and 8.19.4.

Unauthenticated SQL Injection in AcyMailing found by mySites.guru

Unauthenticated SQL Injection in AcyMailing found by mySites.guru

mySites.guru found and reported CVE-2026-56292, an unauthenticated SQL injection in AcyMailing for Joomla and WordPress. Update to 10.11.1 now.

Browse every article