
🚨 CVE-2026-100752 PoC Released OrdaSoft Real Estate Manager for Joomla 🔴 Unauthenticated SQL Injection 📌 Affected: ≤ 6.7.8 ✅ Fixed: 6.7.9+ PoC: https://pocbit.org/pocs/cve-2026-100752 #CVE #Joomla #SQLi #CyberSecurity #InfoSec #PoC
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Real Estate Manager (Free) < 6.7.9 - site/realestatemanager.php builds the ORDER BY clause of three separate frontend property-listing queries (category browsing, search results, and the full property listing) from a request-controlled order_field parameter, concatenated directly into an unquoted SQL clause with no allow-list of real column names and no cast.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
STABLE

🚨 CVE-2026-100752 PoC Released OrdaSoft Real Estate Manager for Joomla 🔴 Unauthenticated SQL Injection 📌 Affected: ≤ 6.7.8 ✅ Fixed: 6.7.9+ PoC: https://pocbit.org/pocs/cve-2026-100752 #CVE #Joomla #SQLi #CyberSecurity #InfoSec #PoC

CVE-2026-100752 Joomla Extension - https://ordasoft.com - Unauthenticated SQL Injection in Real Estate Manager (Free) < 6.7.9 - site/realestatemanager.php builds the ORDER BY clause of thr… https://www.cve.org/CVERecord?id=CVE-2026-100752