CVE-2026-21630Disclosure(joomla / joomla\!)

LOWCVSS 8.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch joomla joomla\! systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improperly built order clauses lead to a SQL injection vulnerability in the articles webservice endpoint.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • joomla\!

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-04-13)
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
joomla\!

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-04-01: 1Mentions · 2026-04-03: 1Mentions · 2026-04-13: 2Patch / Workaround · 2026-04-03: 1Technical Details · 2026-04-01: 1Technical Details · 2026-04-13: 204-0104-0304-13
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-011
Disclosure1
2026-04-031
Patch1
2026-04-132
Disclosure2
Full discourse4 posts
  • CyStack@CyStackSecurity
    Disclosure

    🔓 SECURITY BULLETIN: @CyStackSecurity researcher found CVE-2026-21630 (SQL Injection) and CVE-2026-23899 (Improper Access Control) in Joomla REST API, with medium-to-high severity. Full report: https://cystack.net/research/security-joomla-rest-api #CyStack #Cybersecurity #InfoSec #Joomla #CVE #Vulnerability

    Post summary

    The bulletin announces medium-to-high severity CVE-2026-21630 (SQL Injection) and CVE-2026-23899 (Improper Access Control) in Joomla REST API, and links to a full report.

    00010418
  • CyStack@CyStackSecurity
    Disclosure

    🔓 SECURITY BULLETIN: @CyStackSecurity researchers recently deep-dived into the Joomla REST API. CVE-2026-21630 and CVE-2026-23899 could allow unauthorized attackers to access sensitive data without credentials. Full report: https://cystack.net/research/security-joomla-rest-api

    Post summary

    Researchers announce two Joomla REST API vulnerabilities that could allow unauthenticated attackers to read sensitive data; a linked report provides further details.

    0001011
    3.7K followersView on X
  • Autumn Good@autumn_good_35
    Patch

    CVE-2026-21629 CVE-2026-21630 CVE-2026-21631 CVE-2026-21632 CVE-2026-23898 CVE-2026-23899 Joomla 6.0.4 & 5.4.4 Security & Bugfix Release https://www.joomla.org/announcements/release-news/5944-joomla-6-0-4-5-4-4-security-bugfix-release.html

    Post summary

    Joomla’s security update addresses a set of newly published CVEs, with official patches highlighted in the release announcement.

    00000377
    6.7K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-21630 Improperly built order clauses lead to a SQL injection vulnerability in the articles webservice endpoint. https://www.cve.org/CVERecord?id=CVE-2026-21630

    Post summary

    The post announces CVE‑2026‑21630 as a SQL injection due to improperly built order clauses in an articles webservice, but gives no PoC, exploit, or patch information.

    0000047
    56.9K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appjoomlajoomla\!---

Explore more