Real Estate Manager (com_realestatemanager) below 6.7.9 - Unauthenticated SQL Injection
Real Estate Manager by OrdaSoft before 6.7.9 builds the ORDER BY clause of three public property-listing queries (category browsing, search results and the full property listing) from the request parameter order_field, concatenated into the SQL with no allow-list of column names and no cast. No login is needed. CVE-2026-100752, CVSS 4.0 9.3 Critical. The CVE record names the Free edition; the Pro edition shares the element and version numbering. Update to 6.7.9 or later. If you cannot update, disable the component until you can.
Affected versions: < 6.7.9
Full advisory: our disclosure post