Skip to main content
mySites.guru
New features added last monthRelease RadarFile ManagerImpostor FilesUpdate QueueRogue AdminsMCP & APIJoomla VELCVE Index

Sexy Polling Reloaded security vulnerabilities

mySites.guru tracks 2 vulnerabilities in com_sexypolling. Every connected Joomla site is checked against them on each audit, and flagged if it runs an affected version.

What we check for

HighCVE-2026-780722026-08-28

Sexy Polling Reloaded (com_sexypolling) below 5.0.6.1 (Joomla 3.10 and 4) - Unauthenticated Blind SQL Injection

Sexy Polling Reloaded contains a blind SQL injection that needs no login, no token and no user interaction (CVSS 4.0 vector PR:N, base score 8.7 High), allowing an anonymous visitor to read arbitrary data from the site database. Reported by Krzysztof Zajac of CERT PL. The vendor, Jefferson49, maintains two parallel release lines and shipped the fix to both on 2026-07-25: 5.0.6.1 for the Joomla 3.10 and 4 line, and 5.6.1 for the Joomla 4, 5 and 6 line. Because 5.0.6.1 sorts below 5.6.1, a single rule written to the CVE ceiling of 5.6.1 would wrongly flag the patched legacy build, so this advisory is split into one rule per branch.

Affected versions: ≥ 1.0.0 and < 5.0.6.1

Full advisory: github.com

HighCVE-2026-780722026-08-28

Sexy Polling Reloaded (com_sexypolling) 5.1.0 to 5.6.0 (Joomla 4 to 6) - Unauthenticated Blind SQL Injection

Sexy Polling Reloaded contains a blind SQL injection that needs no login, no token and no user interaction (CVSS 4.0 vector PR:N, base score 8.7 High), allowing an anonymous visitor to read arbitrary data from the site database. Reported by Krzysztof Zajac of CERT PL. The vendor, Jefferson49, maintains two parallel release lines and shipped the fix to both on 2026-07-25: 5.0.6.1 for the Joomla 3.10 and 4 line, and 5.6.1 for the Joomla 4, 5 and 6 line. Because 5.0.6.1 sorts below 5.6.1, a single rule written to the CVE ceiling of 5.6.1 would wrongly flag the patched legacy build, so this advisory is split into one rule per branch.

Affected versions: ≥ 5.1.0 and < 5.6.1

Full advisory: github.com

Running Sexy Polling Reloaded on a site you manage?

A free audit tells you which of your Joomla and WordPress sites run an affected version, which are out of date, and which have not been backed up. No card required. If a site is already compromised, fix.mysites.guru is a single fixed fee per incident, usually resolved the same day.

CVE identifiers: CVE-2026-78072. Rules current as of 13 September 2026.