CVE WATCH / VULNERABILITY DETAIL

CVE-2026-100753

UNKNOWNCVSS 0NVD feed

Published 28 September 2026 · tracked since 29 September 2026

Description

Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Real Estate Manager (Free) < 6.7.9 - The public property-detail page’s “leave a review” form repopulates its title field directly from the request with no escaping and no filtering function of any kind, unlike the adjacent comment

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-100753 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-100753

UNKNOWNCVSS 0NVD feed

Published 28 September 2026 · tracked since 29 September 2026

Description

Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Real Estate Manager (Free) < 6.7.9 - The public property-detail page’s “leave a review” form repopulates its title field directly from the request with no escaping and no filtering function of any kind, unlike the adjacent comment

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]