VYPR
Vypr IntelligenceAI-generatedSep 28, 2026· 13 CVEs

Joomla Extensions: Batch of 13 Vulnerabilities Includes Critical RCE, SQLi, and XSS

Thirteen Joomla extension vulnerabilities, including critical RCE and SQLi, were disclosed in a batch from September 26-28, 2026, affecting multiple vendors.

Key findings

  • Thirteen Joomla extension vulnerabilities disclosed between September 26-28, 2026, including critical RCE and SQLi flaws.
  • Extensions from ordasoft.com, regularlabs.com, svenbluege.de, lomart.fr, and joomlaboat.com are affected.
  • Critical vulnerabilities include unauthenticated RCE, path traversal, and command injection in UP plugin and YouTube Gallery.
  • Medium and High severity flaws include XSS, LFI/SSRF, and arbitrary path deletion across other extensions.
  • Patches are available; immediate updates are recommended for all affected extensions.

On September 28, 2026, a batch of thirteen vulnerabilities was disclosed across several Joomla extensions from multiple vendors, with the earliest disclosures in this batch occurring on September 26, 2026. The vulnerabilities span critical and high severity flaws including unauthenticated remote code execution, SQL injection, path traversal, and cross-site scripting, impacting extensions from ordasoft.com, regularlabs.com, svenbluege.de, lomart.fr, and joomlaboat.com. These disclosures highlight ongoing security risks within the Joomla ecosystem, particularly concerning third-party extensions.

Several extensions from ordasoft.com were affected by medium and critical severity vulnerabilities. The Book Library (Free) extension, prior to version 6.4.6, suffered from Reflected Cross-Site Scripting (CVE-2026-101111) due to improper handling of the 'title' request parameter. Additionally, the same extension contained an Unauthenticated SQL Injection vulnerability (CVE-2026-101110) in its books() function, which failed to adequately sanitize 'field' and 'direction' parameters. Similarly, the Vehicle Manager (Free) extension, before version 6.5.8, had a Reflected Cross-Site Scripting flaw (CVE-2026-101108) in its public vehicle-detail page, echoing the 'title' parameter without proper encoding. This extension also suffered from an Unauthenticated SQL Injection vulnerability (CVE-2026-101108) in its site/vehiclemanager.php file, affecting category listing, search, and all-vehicles listing functionalities. The Real Estate Manager (Free) extension, prior to version 6.7.9, had a Reflected Cross-Site Scripting vulnerability (CVE-2026-100753) in its property-detail page's review form, where the 'title' field was echoed directly from the request.

Extensions from regularlabs.com and svenbluege.de also saw disclosures. Tabs & Accordions (Pro) versions 2.3.0 through 3.1.0 were affected by a High severity Privileged Stored XSS vulnerability (CVE-2026-100751) where a 'url' option could be written to a data-rlta-url attribute, leading to arbitrary JavaScript execution via window.open(). Modules Anywhere (Pro) versions 1.5.0 through 9.0.5 contained a High severity Local File Inclusion (LFI) and Server-Side Request Forgery (SSRF) vulnerability (CVE-2026-100750) due to improper handling of module tag attributes. For the Event Gallery extension from svenbluege.de, versions prior to 6.5.0 had an Authenticated arbitrary path deletion vulnerability (CVE-2026-97164) within its 'clear cache' task, allowing recursive deletion of directories via the 'images' parameter. A separate CSRF vulnerability (CVE-2026-100749) was also found in the backend cleanup actions of the same extension.

A significant cluster of four critical vulnerabilities was disclosed on September 26, 2026, affecting extensions from lomart.fr and joomlaboat.com. The lomart.fr UP plugin, in versions 5.0.0-5.2.0 and 6.0.0-6.0.29, was impacted by Unauthenticated Remote Code Installation (CVE-2026-97163), various Path Traversal/File Access vectors (CVE-2026-97161), and Authenticated, Privileged PHP Command Injection (CVE-2026-97160). The joomlaboat.com YouTube Gallery extension, prior to version 5.7.3, suffered from an Unauthenticated SQL Injection vulnerability (CVE-2026-94130) in its video search and sorting functionality. These critical flaws, particularly the RCE and command injection vulnerabilities, pose a severe risk to Joomla sites utilizing these extensions.

The vulnerabilities were patched in updated versions of the respective extensions. Users are strongly advised to update the ordasoft.com Book Library to 6.4.6+, Vehicle Manager to 6.5.8+, Real Estate Manager to 6.7.9+, Tabs & Accordions Pro to 3.1.1+, Modules Anywhere to 9.0.6+, Event Gallery to 6.5.0+, UP plugin to 6.0.30+ or 5.2.1+, and YouTube Gallery to 5.7.3+. Prompt patching is crucial to mitigate the risks associated with these vulnerabilities, especially the critical remote code execution and SQL injection flaws that could lead to complete site compromise.

This batch of thirteen vulnerabilities underscores the importance of regularly auditing and updating third-party Joomla extensions. The concentration of critical flaws, including RCE and SQLi, across multiple vendors within a short disclosure window highlights a persistent threat landscape for Joomla administrators. Staying informed about security advisories and applying patches promptly remains the most effective defense against such widespread vulnerabilities.

CVE-2026-101111, CVE-2026-101110, CVE-2026-101109, CVE-2026-101108, CVE-2026-100753, CVE-2026-100751, CVE-2026-100750, CVE-2026-97164, CVE-2026-100749, CVE-2026-97163, CVE-2026-97161, CVE-2026-97160, CVE-2026-94130

AI-written article. Grounded in 13 CVE records listed below.