Critical severityNVD Advisory· Published Sep 28, 2026
CVE-2026-100752
CVE-2026-100752
Description
Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Real Estate Manager (Free) < 6.7.9 - site/realestatemanager.php builds the ORDER BY clause of three separate frontend property-listing queries (category browsing, search results, and the full property listing) from a request-controlled order_field parameter, concatenated directly into an unquoted SQL clause with no allow-list of real column names and no cast.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <6.7.9
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.