CVE-2026-102427
Published 30 September 2026 · tracked since 1 October 2026
Description
Joomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in OrdaSoft Joomla CCK < 8.3.16 - site/uploader.php is reached through the component’s normal frontend routing (task=getContent), a task with no authentication or ACL check anywhere in the dispatch chain. The handler validates t
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-102377 HIGH 8.8
- CVE-2026-100512 CRITICAL 9.8
- CVE-2026-62308 CRITICAL 9.1
- CVE-2026-55494 CRITICAL 9.8
- CVE-2026-46711 HIGH 8.3
- CVE-2026-55181 CRITICAL 9.4
- CVE-2026-47571 HIGH 7.8
- CVE-2026-47573 HIGH 7.8
- CVE-2026-47575 HIGH 7.8
- CVE-2026-47570 HIGH 7.8