Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 30 Sep 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Joomla Extension - joomcode.com - Unauthenticated SQL injection in read and write queries in JCTables 1.21.1 - The front-end CRUD API controller performs no Joomla token validation and no authentication check on any task. Table names, column names, and values are taken directly from request parameters and concatenated into SQL queries, allowing SQLi for reading and writing queries. | |
| Title | Joomla Extension - joomcode.com - Unauthenticated SQL injection in read and write queries in JCTables < 1.21.1 | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Joomla
Published:
Updated: 2026-09-30T16:10:53.173Z
Reserved: 2026-08-19T13:43:47.173Z
Link: CVE-2026-76570
No data.
Status : Awaiting Analysis
Published: 2026-09-30T15:22:34.903
Modified: 2026-09-30T16:44:39.840
Link: CVE-2026-76570
No data.
OpenCVE Enrichment
Updated: 2026-09-30T17:45:05Z
-
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')