Vehicle Manager (com_vehiclemanager) below 6.5.8 - Unauthenticated SQL Injection
Vehicle Manager by OrdaSoft before 6.5.8 reads the order_field and order_direction sort parameters at three public entry points (category listing, search and the all-vehicles listing). The values are escaped, but they are placed into an unquoted ORDER BY clause where escaping gives no protection. No login is needed. CVE-2026-101108, CVSS 4.0 9.3 Critical. The CVE record names the Free edition; the Pro edition shares the element and version numbering. Update to 6.5.8 or later. If you cannot update, disable the component until you can.
Affected versions: < 6.5.8
Full advisory: our disclosure post