Affected versions: ≥ 1.0.0 and < 5.0.6.1
Full advisory: github.com
Sexy Polling Reloaded contains a blind SQL injection that needs no login, no token and no user interaction (CVSS 4.0 vector PR:N, base score 8.7 High), allowing an anonymous visitor to read arbitrary data from the site database. Reported by Krzysztof Zajac of CERT PL. The vendor, Jefferson49, maintains two parallel release lines and shipped the fix to both on 2026-07-25: 5.0.6.1 for the Joomla 3.10 and 4 line, and 5.6.1 for the Joomla 4, 5 and 6 line. Because 5.0.6.1 sorts below 5.6.1, a single rule written to the CVE ceiling of 5.6.1 would wrongly flag the patched legacy build, so this advisory is split into one rule per branch.
Affected versions: ≥ 1.0.0 and < 5.0.6.1
Official record: cve.org · NVD
Every connected Joomla site is checked against these rules on each audit, and flagged if it runs an affected version.
The base metrics as Joomla CNA published them, and what each one means for a site running an affected version. Threat and environmental metrics are left out: they describe a moment or a particular install rather than the flaw.
8.7 High
CVSS 4.0, scored by Joomla CNACVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:NAffected versions: ≥ 1.0.0 and < 5.0.6.1
Full advisory: github.com
Sexy Polling Reloaded - Sexy Polling Reloaded (com_sexypolling) 5.1.0 to 5.6.0 (Joomla 4 to 6) - Unauthenticated Blind SQL Injection
Sexy Polling Reloaded contains a blind SQL injection that needs no login, no token and no user interaction (CVSS 4.0 vector PR:N, base score 8.7 High), allowing an anonymous visitor to read arbitrary data from the site database. Reported by Krzysztof Zajac of CERT PL. The vendor, Jefferson49, maintains two parallel release lines and shipped the fix to both on 2026-07-25: 5.0.6.1 for the Joomla 3.10 and 4 line, and 5.6.1 for the Joomla 4, 5 and 6 line. Because 5.0.6.1 sorts below 5.6.1, a single rule written to the CVE ceiling of 5.6.1 would wrongly flag the patched legacy build, so this advisory is split into one rule per branch. If you have updated to 5.6.1, the Joomla backend shows 5.6.1 for every Sexy Polling part, and this warning still says Installed 5.5.x, the cause is a leftover file rather than an unpatched site. At 5.6.x Jefferson49 renamed the extension's XML manifest files and Joomla does not remove the old ones, so an old sexypolling.xml from 5.5.x is still sitting next to the new manifests, and mySites.guru reads the old file first. To clear the warning, delete only these three leftover files: administrator/components/com_sexypolling/sexypolling.xml, plugins/system/sexypolling/sexypolling.xml and plugins/editors-xtd/sexypolling/sexypolling.xml. Keep com_sexypolling.xml, plg_sexypolling.xml and plg_editorbutton.xml in the same folders. The leftovers are old descriptions, not code, so deleting them leaves the site the same as a fresh 5.6.1 install, and the warning clears at the next snapshot.
Affected versions: ≥ 5.1.0 and < 5.6.1
Full advisory: github.com
A free audit tells you which of your Joomla and WordPress sites run an affected version, which are out of date, and which have not been backed up. No card required. If a site is already compromised, fix.mysites.guru is a single fixed fee per incident, usually resolved the same day.
Rules current as of 3 October 2026.