VulnSea

ordasoft.com has 10 CVEs on record. Disclosure cadence is accelerating: 10 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 10. The median CVSS is 9.3 (critical), with 6 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-89 (5) and CWE-79 (3). Most affected products: com_osgallery_light (4), com_booklibrary (2), com_realestatemanager (2).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
9.3
Publish → KEV
—
Last 90 days
10 prev 0

Products

  • com_osgallery_light 4
  • com_booklibrary 2
  • com_realestatemanager 2
  • com_vehiclemanager 2
10
Total CVEs
6
Critical
0
CISA KEV
0
Exploited

ordasoft.com vulnerabilities

CVEs affecting ordasoft.com, newest first. Open any entry for full detail, references, and exploit status.

10 CVEsRSS

CVE-2026-101111Medium· 5.3
today

Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Book Library (Free) < 6.4.6 - The public book-detail page template, site/views/view_book/tmpl/default.php, echoes the raw title request parameter directly into a double-…

Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Book Library (Free) < 6.4.6 - The public book-detail page template, site/views/view_book/tmpl/default.php, echoes the raw title request parameter directly into a double-…

▾ Sunlitordasoft.com · com_booklibraryvia NVD
CVE-2026-101110Critical· 9.3
today

Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Book Library (Free) < 6.4.6 - site/booklibrary.php’s books() function reads the field and direction request parameters and passes each through a function called protectIn…

Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Book Library (Free) < 6.4.6 - site/booklibrary.php’s books() function reads the field and direction request parameters and passes each through a function called protectIn…

▾ Midnightordasoft.com · com_booklibraryvia NVD
CVE-2026-101109Medium· 5.3
today

Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Vehicle Manager (Free) < 6.5.8 - The public vehicle-detail page (task=view) echoes the title request parameter directly into a double-quoted HTML attribute with no outpu…

Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Vehicle Manager (Free) < 6.5.8 - The public vehicle-detail page (task=view) echoes the title request parameter directly into a double-quoted HTML attribute with no outpu…

▾ Sunlitordasoft.com · com_vehiclemanagervia NVD
CVE-2026-101108Critical· 9.3
today

Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Vehicle Manager (Free) < 6.5.8 - site/vehiclemanager.php reads the order_field and order_direction sort parameters at three separate anonymous-reachable frontend entry po…

Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Vehicle Manager (Free) < 6.5.8 - site/vehiclemanager.php reads the order_field and order_direction sort parameters at three separate anonymous-reachable frontend entry po…

▾ Midnightordasoft.com · com_vehiclemanagervia NVD
CVE-2026-100753Medium· 5.3
today

Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Real Estate Manager (Free) < 6.7.9 - The public property-detail page’s “leave a review” form repopulates its title field directly from the request with no escaping and …

Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Real Estate Manager (Free) < 6.7.9 - The public property-detail page’s “leave a review” form repopulates its title field directly from the request with no escaping and …

▾ Sunlitordasoft.com · com_realestatemanagervia NVD
CVE-2026-100752Critical· 9.3
today

Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Real Estate Manager (Free) < 6.7.9 - site/realestatemanager.php builds the ORDER BY clause of three separate frontend property-listing queries (category browsing, search …

Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Real Estate Manager (Free) < 6.7.9 - site/realestatemanager.php builds the ORDER BY clause of three separate frontend property-listing queries (category browsing, search …

▾ Midnightordasoft.com · com_realestatemanagervia NVD
CVE-2026-88857Critical· 9.4
1w ago

Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions saveWatermark() copied an uploaded file into a web-accessible directory using the …

Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions saveWatermark() copied an uploaded file into a web-accessible directory using the …

▾ MidnightOrdaSoft.com · com_osgallery_lightEPSS 0.64%via NVD
CVE-2026-88856Critical· 9.4
1w ago

Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions updateOSGallery(), reached via task=update_osgallery, read a JSON request body and…

Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions updateOSGallery(), reached via task=update_osgallery, read a JSON request body and…

▾ MidnightOrdaSoft.com · com_osgallery_lightEPSS 0.67%via NVD
CVE-2026-88855High· 8.6
1w ago

Joomla Extension - OrdaSoft.com - Authenticated, Privileged SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions saveGallery() passes form data through a hand-rolled parser into Joomla’s Input object, th…

Joomla Extension - OrdaSoft.com - Authenticated, Privileged SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions saveGallery() passes form data through a hand-rolled parser into Joomla’s Input object, th…

▾ TwilightOrdaSoft.com · com_osgallery_lightEPSS 0.37%via NVD
CVE-2026-88854Critical· 9.3PoC
1w ago

Joomla Extension - OrdaSoft.com - Unauthenticated SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions showSearchResult() and showSearchResultAjax() read the textsearch/searchText request parameter with …

Joomla Extension - OrdaSoft.com - Unauthenticated SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions showSearchResult() and showSearchResultAjax() read the textsearch/searchText request parameter with …

▾ AbyssalOrdaSoft.com · com_osgallery_lightEPSS 0.39%via NVD
ordasoft.com vulnerabilities (CVEs) · VulnSea