Book Library (com_booklibrary) below 6.4.6 - Unauthenticated SQL Injection
Book Library by OrdaSoft before 6.4.6 passes the field and direction request parameters of its public book listing through protectInjectionWithoutQuote(), a keyword blacklist that quotes rather than rejects a suspicious value, and then concatenates the result into an unquoted ORDER BY clause where quoting gives no protection. No login is needed. CVE-2026-101110, CVSS 4.0 9.3 Critical. The CVE record names the Free edition; the Pro and ShopPro editions share the element and version numbering. The record title gives the fix as 6.4.6 while its affected range runs to 6.4.6; update to the newest release OrdaSoft offers. If you cannot update, disable the component until you can.
Affected versions: < 6.4.6
Full advisory: our disclosure post