VYPR

Book Library (Free)

by Ordasoft.com

CVEs (1)

  • CVE-2026-101110CriSep 28, 2026
    risk 0.60cvss —epss —

    Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Book Library (Free) < 6.4.6 - site/booklibrary.php’s books() function reads the field and direction request parameters and passes each through a function called protectInjectionWithoutQuote(), whose only real…