Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-100752: Joomla Real Estate Manager lets attackers read database

CVE-2026-100752 · published 4 days ago
Summary

The free Real Estate Manager extension for Joomla lets anyone on the internet send a specially crafted request that changes the way the site builds its property listings. By doing this, an attacker can retrieve information from the website’s database without logging in. Upgrade the extension to version 6.7.9 or later, or apply the vendor’s patch, to stop this behavior.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
ordasoft.com real estate manager (free) extension for joomla 1.0.0-6.7.8
Original advisory text
Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Real Estate Manager (Free) < 6.7.9
Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Real Estate Manager (Free) < 6.7.9 - site/realestatemanager.php builds the ORDER BY clause of three separate frontend property-listing queries (category browsing, search results, and the full property listing) from a request-controlled order_field parameter, concatenated directly into an unquoted SQL clause with no allow-list of real column names and no cast.
References
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.3 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-89SQL Injection
Timeline
Published28 Sep 2026
Updated2 Oct 2026
First seen28 Sep 2026
Sources
CVE-2026-100752 · MITRE
Track software like this
Free during beta