Skip to main content
mySites.guru
J!Awards 2026mySites.guru is shortlisted for Your Favourite Tool in Your Joomla WorkflowVote by 11 OctoberHow to vote

Sexy Polling Reloaded security vulnerabilities

mySites.guru tracks 2 vulnerabilities in com_sexypolling. Every connected Joomla site is checked against them on each audit, and flagged if it runs an affected version.

What we check for

HighCVE-2026-780722026-08-28

Sexy Polling Reloaded (com_sexypolling) below 5.0.6.1 (Joomla 3.10 and 4) - Unauthenticated Blind SQL Injection

Sexy Polling Reloaded contains a blind SQL injection that needs no login, no token and no user interaction (CVSS 4.0 vector PR:N, base score 8.7 High), allowing an anonymous visitor to read arbitrary data from the site database. Reported by Krzysztof Zajac of CERT PL. The vendor, Jefferson49, maintains two parallel release lines and shipped the fix to both on 2026-07-25: 5.0.6.1 for the Joomla 3.10 and 4 line, and 5.6.1 for the Joomla 4, 5 and 6 line. Because 5.0.6.1 sorts below 5.6.1, a single rule written to the CVE ceiling of 5.6.1 would wrongly flag the patched legacy build, so this advisory is split into one rule per branch.

Affected versions: ≥ 1.0.0 and < 5.0.6.1

Full advisory: github.com

HighCVE-2026-780722026-08-28

Sexy Polling Reloaded (com_sexypolling) 5.1.0 to 5.6.0 (Joomla 4 to 6) - Unauthenticated Blind SQL Injection

Sexy Polling Reloaded contains a blind SQL injection that needs no login, no token and no user interaction (CVSS 4.0 vector PR:N, base score 8.7 High), allowing an anonymous visitor to read arbitrary data from the site database. Reported by Krzysztof Zajac of CERT PL. The vendor, Jefferson49, maintains two parallel release lines and shipped the fix to both on 2026-07-25: 5.0.6.1 for the Joomla 3.10 and 4 line, and 5.6.1 for the Joomla 4, 5 and 6 line. Because 5.0.6.1 sorts below 5.6.1, a single rule written to the CVE ceiling of 5.6.1 would wrongly flag the patched legacy build, so this advisory is split into one rule per branch. If you have updated to 5.6.1, the Joomla backend shows 5.6.1 for every Sexy Polling part, and this warning still says Installed 5.5.x, the cause is a leftover file rather than an unpatched site. At 5.6.x Jefferson49 renamed the extension's XML manifest files and Joomla does not remove the old ones, so an old sexypolling.xml from 5.5.x is still sitting next to the new manifests, and mySites.guru reads the old file first. To clear the warning, delete only these three leftover files: administrator/components/com_sexypolling/sexypolling.xml, plugins/system/sexypolling/sexypolling.xml and plugins/editors-xtd/sexypolling/sexypolling.xml. Keep com_sexypolling.xml, plg_sexypolling.xml and plg_editorbutton.xml in the same folders. The leftovers are old descriptions, not code, so deleting them leaves the site the same as a fresh 5.6.1 install, and the warning clears at the next snapshot.

Affected versions: ≥ 5.1.0 and < 5.6.1

Full advisory: github.com

Running Sexy Polling Reloaded on a site you manage?

A free audit tells you which of your Joomla and WordPress sites run an affected version, which are out of date, and which have not been backed up. No card required. If a site is already compromised, fix.mysites.guru is a single fixed fee per incident, usually resolved the same day.

CVE identifiers: CVE-2026-78072. Rules current as of 3 October 2026.