VYPR

Book Library (Free)

by Joomla

CVEs (2)

  • CVE-2026-101110CriSep 28, 2026
    risk 0.60cvss —epss —

    Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Book Library (Free) < 6.4.6 - site/booklibrary.php’s books() function reads the field and direction request parameters and passes each through a function called protectInjectionWithoutQuote(), whose only real…

  • CVE-2026-101111MedSep 28, 2026
    risk 0.34cvss —epss —

    Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Book Library (Free) < 6.4.6 - The public book-detail page template, site/views/view_book/tmpl/default.php, echoes the raw title request parameter directly into a double-quoted HTML attribute with no escaping…