Medium severityNVD Advisory· Published Sep 28, 2026
CVE-2026-101109
CVE-2026-101109
Description
Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Vehicle Manager (Free) < 6.5.8 - The public vehicle-detail page (task=view) echoes the title request parameter directly into a double-quoted HTML attribute with no output encoding of any kind. A double-quote character in the parameter closes the attribute, allowing arbitrary markup, including a tag, to be injected into the page.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <6.5.8
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.