CVE-2026-49048
EUVD-2026-4000328.06.2026, 19:16
The Joomla extension JoomCCK exposes a front-end controller task, that builds two SQL statements by directly concatenating a user-supplied request parameter into the query string without escaping or parameterisation.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| joomcoder | joomcck | 1.0 ≤ 𝑥 ≤ 6.4.0 |
𝑥
= Vulnerable software versions
References