Export limit exceeded: 400567 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 400567 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (1 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-101111 | 2 Ordasoft, Ordasoft.com | 2 Book Library, Book Library (free) Extension For Joomla | 2026-10-01 | 6.1 Medium |
| Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Book Library (Free) < 6.4.6 - The public book-detail page template, site/views/view_book/tmpl/default.php, echoes the raw title request parameter directly into a double-quoted HTML attribute with no escaping function of any kind (echo $_REQUEST["title"];). A value containing a double quote closes the attribute early and allows arbitrary HTML/JavaScript to follow. | ||||
Page 1 of 1.