PT-2026-53162 · Undefined · Undefined
Published
2026-06-28
·
Updated
2026-06-28
·
CVE-2026-49048
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
The Joomla extension JoomCCK exposes a front-end controller task, that builds two SQL statements by directly concatenating a user-supplied request parameter into the query string without escaping or parameterisation.
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Undefined