---
id: CVE-2026-76570
title: >-
  Joomla Extension - joomcode.com - Unauthenticated SQL injection in read and
  write queries in JCTables  1.21.1 - The front-end CRUD API controller performs
  no Joomla token validation and no authentication check on any task
summary: >-
  Joomla Extension - joomcode.com - Unauthenticated SQL injection in read and
  write queries in JCTables  1.21.1 - The front-end CRUD API controller performs
  no Joomla token validation and no authentication check on any task. Table
  names, c…
severity: critical
cvss: 10
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/AU:Y'
cwe:
  - CWE-89
vendor: joomcode.com
product: JCTables extension for Joomla
affected:
  - jctables_extension_for_joomla 1.0.0-1.20.0
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T16:44:39.840'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-76570'
references:
  - url: 'https://www.joomcode.com/'
    label: security@joomla.org
  - url: 'https://www.vulncheck.com/blog/jctables-unauthenticated-sql-rw-to-rce'
    label: security@joomla.org
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-09-30T14:59:27.938634Z'
cvssSource: cna
ingestedAt: '2026-09-30T15:07:05.377Z'
---

## Overview

Joomla Extension - joomcode.com - Unauthenticated SQL injection in read and write queries in JCTables  1.21.1 - The front-end CRUD API controller performs no Joomla token validation and no authentication check on any task. Table names, column names, and values are taken directly from request parameters and concatenated into SQL queries, allowing SQLi for reading and writing queries.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
