VYPR

OrdaSoft Simple Membership

by Ordasoft.com

CVEs (1)

  • CVE-2026-102782CriOct 7, 2026
    risk 0.60cvss —epss —

    Joomla Extension - ordasoft.com - Unauthenticated SQL injection in OrdaSoft Simple Membership < 7.4.0 - site/simplemembership.php dispatches task=checkLoginPass with no authentication or access control check of any kind. The handler reads a login request parameter through…