CVE WATCH / VULNERABILITY DETAIL

CVE-2026-102427

CRITICALCVSS 10NVD feed

Published 30 September 2026 · tracked since 1 October 2026

Description

Joomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in OrdaSoft Joomla CCK < 8.3.16 - site/uploader.php is reached through the component’s normal frontend routing (task=getContent), a task with no authentication or ACL check anywhere in the dispatch chain. The handler validates t

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-102427 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-102427

CRITICALCVSS 10NVD feed

Published 30 September 2026 · tracked since 1 October 2026

Description

Joomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in OrdaSoft Joomla CCK < 8.3.16 - site/uploader.php is reached through the component’s normal frontend routing (task=getContent), a task with no authentication or ACL check anywhere in the dispatch chain. The handler validates t

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]