Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-100752: Joomla Real Estate Manager lets attackers read database
CVE-2026-100752 · published 4 days ago
Summary
The free Real Estate Manager extension for Joomla lets anyone on the internet send a specially crafted request that changes the way the site builds its property listings. By doing this, an attacker can retrieve information from the website’s database without logging in. Upgrade the extension to version 6.7.9 or later, or apply the vendor’s patch, to stop this behavior.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| ordasoft.com | real estate manager (free) extension for joomla | 1.0.0-6.7.8 |
Original advisory text
Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Real Estate Manager (Free) < 6.7.9
Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Real Estate Manager (Free) < 6.7.9 - site/realestatemanager.php builds the ORDER BY clause of three separate frontend property-listing queries (category browsing, search results, and the full property listing) from a request-controlled order_field parameter, concatenated directly into an unquoted SQL clause with no allow-list of real column names and no cast.
References
- https://www.ordasoft.com/ product
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Type
CWE-89SQL Injection
Timeline
Published28 Sep 2026
Updated2 Oct 2026
First seen28 Sep 2026
Track software like this
Free during beta