PT-2026-103298 · Joomla · Jctables

·

CVE-2026-76570

·

Published

2026-09-30

·

Updated

2026-10-02

CVSS v4.0

10

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/AU:Y
Name of the Vulnerable Software and Affected Versions JCTables version 1.21.1
Description An unauthenticated SQL injection exists in the front-end CRUD API controller. The component fails to perform Joomla token validation and authentication checks on any task. Table names, column names, and values are taken directly from request parameters and concatenated into SQL queries, enabling unauthorized read and write operations.
Recommendations Update JCTables to a version newer than 1.21.1.

Fix

RCE

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76570

Affected Products

Jctables