Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-101109— Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Vehicle Manager (Free) < 6.5.8

Quick assessment

Affected
ordasoft.com Vehicle Manager (Free) extension for Joomla
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Joomla 扩展 - ordasoft.com - Vehicle Manager(免费版)< 6.5.8 中存在反射型跨站脚本漏洞。在公开的车辆详情页面(task=view)中,系统会将 title 请求参数的值直接输出到一个双引号包裹的 HTML 属性中,且未进行任何形式的输出编码。如果参数中包含双引号字符,将会闭合该 HTML 属性,从而允许任意标记(包括 标签)被注入到页面中。

CVSS 5.3 · Medium

Possible ATT&CK Techniques 1 AI

T1189 · Drive-by Compromise

Affected Version Matrix 1

VendorProduct Version RangeStatus
ordasoft.com Vehicle Manager (Free) extension for Joomla 1.0.0-6.5.7 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-101109

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Vehicle Manager (Free) < 6.5.8
Source: CVE Program / CVE List V5
Vulnerability Description
Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Vehicle Manager (Free) < 6.5.8 - The public vehicle-detail page (task=view) echoes the title request parameter directly into a double-quoted HTML attribute with no output encoding of any kind. A double-quote character in the parameter closes the attribute, allowing arbitrary markup, including a <script> tag, to be injected into the page.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
ordasoft.com Vehicle Manager (Free) extension for Joomla 1.0.0-6.5.7 -

II. Public POCs for CVE-2026-101109

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-101109

请登录查看更多情报信息。

Other References for CVE-2026-101109 (1)

Same Patch Batch · ordasoft.com · 2026-09-28 · 6 CVEs total

CVE-2026-100752 9.3 CRITICAL Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Real Estate Manager (Fr
CVE-2026-101110 9.3 CRITICAL Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Book Library (Free) < 6
CVE-2026-101108 9.3 CRITICAL Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Vehicle Manager (Free)
CVE-2026-100753 5.3 MEDIUM Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Real Estate Manager (F
CVE-2026-101111 5.3 MEDIUM Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Book Library (Free) <

IV. Related Vulnerabilities

V. Comments for CVE-2026-101109

No comments yet


Leave a comment