Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.7

CVE-2026-49048: Joomla JoomCCK extension allows SQL injection

CVE-2026-49048
Summary

A Joomla extension called JoomCCK has a security flaw that can allow hackers to inject malicious SQL code into the website. This can lead to unauthorized access to sensitive data or even take control of the website. Users should update the extension to the latest version to fix this issue.

Original title
The Joomla extension JoomCCK exposes a front-end controller task, that builds two SQL statements by directly concatenating a user-supplied request parameter into the query string without escaping o...
Original description
The Joomla extension JoomCCK exposes a front-end controller task, that builds two SQL statements by directly concatenating a user-supplied request parameter into the query string without escaping or parameterisation.
Vulnerability type
CWE-89 SQL Injection
Published: 28 Jun 2026 · Updated: 23 Jul 2026 · First seen: 28 Jun 2026