
CVE-2026-76570: unauth SQLi in JCTables (JoomCode's Joomla data-table), read/write to RCE. No auth, no CSRF, broken escaping. One request leaks the admin creds, then reset the password, log in, and drop a webshell. Affected through 1.10.31.2, fixed 1.21.1. https://www.vulncheck.com/blog/jctables-unauthenticated-sql-rw-to-rce






