Skip to main content
mySites.guru
J!Awards 2026mySites.guru is shortlisted for Your Favourite Tool in Your Joomla WorkflowVote by 11 OctoberHow to vote

OS CCK security vulnerabilities

mySites.guru tracks 2 vulnerabilities in com_os_cck. Every connected Joomla site is checked against them on each audit, and flagged if it runs an affected version.

What we check for

CriticalCVE-2026-1024272026-09-30

OS CCK (com_os_cck) below 8.3.16 - Unauthenticated Arbitrary File Upload (RCE)

OrdaSoft OS CCK versions 1.0.0 to 8.3.15 let anyone upload and run PHP on the site with no login. The front-end upload handler (site/uploader.php, reached through the component's normal routing as task=getContent) has no authentication or permission check. It checks the uploaded file's content with a magic-byte MIME test, but the file-extension allow-list that should restrict the saved name was commented out, so the extension is taken straight from the attacker's filename and the file is written under the site's /images folder, where PHP executes it. A file that starts with valid image bytes and has PHP appended passes the check as a .php file. CVE-2026-102427, CVSS 4.0 10.0 Critical. OrdaSoft fixed this in 8.3.16 by enforcing a jpg/jpeg/png/gif/webp extension allow-list. OrdaSoft's Joomla update manifest still advertises 8.3.14, so sites are not offered 8.3.16 automatically: download it from ordasoft.com and install it by hand. The Pro edition shares the element; its fixed version could not be confirmed. If you cannot update, disable the component, and check /images/com_os_cck*/original/ for any .php file.

Affected versions: ≥ 1.0.0 and < 8.3.16

Full advisory: our disclosure post

High

OS CCK (com_os_cck) below 8.3.16 - SQL Injection in record sorting

OrdaSoft OS CCK versions before 8.3.16 (Light/free line) are affected by a SQL injection in the front-end listing views, where the record-sort parameters (order_field / order_direction) were passed into the query ORDER BY clause without being restricted to known-safe columns. OrdaSoft fixed this in 8.3.16 (released 29 September 2026) by validating the sort field against the real entity columns, alongside image-upload and file-handling hardening. This is the same class as four OrdaSoft extension flaws disclosed in the same September 2026 wave - Real Estate Manager (CVE-2026-100752), Vehicle Manager (CVE-2026-101108), Book Library (CVE-2026-101110) and OS Gallery (CVE-2026-88854) - all unauthenticated SQL injection via the same sort parameters on publicly reachable listing pages. No CVE has been assigned to OS CCK at the time of writing. Important: OrdaSoft's own Joomla update manifest still advertises 8.3.14, so affected sites are NOT offered 8.3.16 automatically and must update manually from ordasoft.com. The Pro-edition fixed version could not be independently confirmed. Update to 8.3.16 or later.

Affected versions: < 8.3.16

Full advisory: our disclosure post

Running OS CCK on a site you manage?

A free audit tells you which of your Joomla and WordPress sites run an affected version, which are out of date, and which have not been backed up. No card required. If a site is already compromised, fix.mysites.guru is a single fixed fee per incident, usually resolved the same day.

CVE identifiers: CVE-2026-102427. Rules current as of 30 September 2026.