Joomla · Joomcck · CVE-2026-49048
**Name of the Vulnerable Software and Affected Versions**
JoomCCK (affected versions not specified)
**Description**
A front-end controller task in the JoomCCK extension for Joomla is susceptible to SQL injection. This occurs because the application constructs two SQL statements by directly concatenating a user-supplied request parameter into the query string without proper escaping or parameterization.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.