SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-78080

CRITICAL · CVSS 9.3 EPSS 0.28%

Source: NVD + CISA KEV + EPSS · Published 2026-09-03 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The JooDatabase Lite extension for Joomla versions prior to 5.1.0 is vulnerable to unauthenticated SQL injection due to insufficient validation of the 'cid' parameter in database queries. This critical vulnerability could allow attackers to execute arbitrary SQL commands, potentially compromising the integrity and confidentiality of the database. Joomla administrators and users of the affected extension should prioritize immediate updates to mitigate the risk of exploitation.

CVE
CVE-2026-78080
Severity
CRITICAL
CVSS
9.3
EPSS
0.28%

Original NVD Description

Joomla Extension - feenders.de - Unauthenticated SQL injection in JooDatabase Lite < 5.1.0 - The cid parameter is used in queries without validation, allowing SQLi vectors.