CVE-2026-102427P2CRITICALCVSS 10.0≥ 1.0.0, < 8.3.162026-09-30
CVE-2026-102427 [CRITICAL] CWE-434 CVE-2026-102427: Joomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in OrdaSoft Joomla CCK < 8.3
Joomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in OrdaSoft Joomla CCK < 8.3.16 - site/uploader.php is reached through the component’s normal frontend routing (task=getContent), a task with no authentication or ACL check anywhere in the dispatch chain. The handler validates the uploaded file’s content with a real magic-by
nvd