CVE-2026-76602
published 2026-08-22CVE-2026-76602: Joomla Extension - fabrikar.com - Unauthenticated SQL injection in ORDER BY in Fabrik < 4.7.2 - The order parameter in list models is used in queries without…
PriorityP358critical9.3CVSS 4.0
AVNACLATNPRNUINVCHVIHVAHSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.39%
30.0th percentile
Joomla Extension - fabrikar.com - Unauthenticated SQL injection in ORDER BY in Fabrik < 4.7.2 - The order parameter in list models is used in queries without validation, allowing read SQLi vectors.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fabrikar.com | fabrik_extension_for_joomla | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
fabrikar Fabrik Extension up to 4.7.2 List Models order sql injection
vuldb·2026-08-24·CVSS 9.3
CVE-2026-76602 [CRITICAL] fabrikar Fabrik Extension up to 4.7.2 List Models order sql injection
A vulnerability, which was classified as critical, was found in fabrikar Fabrik Extension up to 4.7.2. This issue affects some unknown processing of the component List Models. Executing a manipulation of the argument order can lead to sql injection.
The identification of this vulnerability is CVE-2026-76602. The attack may be launched remotely. There is no exploit available.
GHSA
Joomla Extension - fabrikar.com - Unauthenticated SQL injection in ORDER BY in Fabrik < 4.7.3 - The order parameter in list models is used in queries without validation, allowing read SQLi vectors.
ghsa_unreviewed·2026-08-22
CVE-2026-76602 [CRITICAL] CWE-89 Joomla Extension - fabrikar.com - Unauthenticated SQL injection in ORDER BY in Fabrik < 4.7.3 - The order parameter in list models is used in queries without validation, allowing read SQLi vectors.
Joomla Extension - fabrikar.com - Unauthenticated SQL injection in ORDER BY in Fabrik < 4.7.3 - The order parameter in list models is used in queries without validation, allowing read SQLi vectors.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-22
Published