CVE-2026-49048
EUVD-2026-4000328.06.2026, 19:16
The Joomla extension JoomCCK exposes a front-end controller task, that builds two SQL statements by directly concatenating a user-supplied request parameter into the query string without escaping or parameterisation.
Awaiting analysis
This vulnerability is currently awaiting analysis.
References