Sexy Polling Reloaded (com_sexypolling) below 5.0.6.1 (Joomla 3.10 and 4) - Unauthenticated Blind SQL Injection
Sexy Polling Reloaded contains a blind SQL injection that needs no login, no token and no user interaction (CVSS 4.0 vector PR:N, base score 8.7 High), allowing an anonymous visitor to read arbitrary data from the site database. Reported by Krzysztof Zajac of CERT PL. The vendor, Jefferson49, maintains two parallel release lines and shipped the fix to both on 2026-07-25: 5.0.6.1 for the Joomla 3.10 and 4 line, and 5.6.1 for the Joomla 4, 5 and 6 line. Because 5.0.6.1 sorts below 5.6.1, a single rule written to the CVE ceiling of 5.6.1 would wrongly flag the patched legacy build, so this advisory is split into one rule per branch.
Affected versions: ≥ 1.0.0 and < 5.0.6.1
Full advisory: github.com
Sexy Polling Reloaded (com_sexypolling) 5.1.0 to 5.6.0 (Joomla 4 to 6) - Unauthenticated Blind SQL Injection
Sexy Polling Reloaded contains a blind SQL injection that needs no login, no token and no user interaction (CVSS 4.0 vector PR:N, base score 8.7 High), allowing an anonymous visitor to read arbitrary data from the site database. Reported by Krzysztof Zajac of CERT PL. The vendor, Jefferson49, maintains two parallel release lines and shipped the fix to both on 2026-07-25: 5.0.6.1 for the Joomla 3.10 and 4 line, and 5.6.1 for the Joomla 4, 5 and 6 line. Because 5.0.6.1 sorts below 5.6.1, a single rule written to the CVE ceiling of 5.6.1 would wrongly flag the patched legacy build, so this advisory is split into one rule per branch. If you have updated to 5.6.1, the Joomla backend shows 5.6.1 for every Sexy Polling part, and this warning still says Installed 5.5.x, the cause is a leftover file rather than an unpatched site. At 5.6.x Jefferson49 renamed the extension's XML manifest files and Joomla does not remove the old ones, so an old sexypolling.xml from 5.5.x is still sitting next to the new manifests, and mySites.guru reads the old file first. To clear the warning, delete only these three leftover files: administrator/components/com_sexypolling/sexypolling.xml, plugins/system/sexypolling/sexypolling.xml and plugins/editors-xtd/sexypolling/sexypolling.xml. Keep com_sexypolling.xml, plg_sexypolling.xml and plg_editorbutton.xml in the same folders. The leftovers are old descriptions, not code, so deleting them leaves the site the same as a fresh 5.6.1 install, and the warning clears at the next snapshot.
Affected versions: ≥ 5.1.0 and < 5.6.1
Full advisory: github.com