System running
Last check: 2026-09-29 00:26:08 | Auto-updates every hour
754 PoCs
CybersecPlayground | The ultimate platform for cybersecurity learning & Bug Bounty Resources

CVE-CVE-2026-100752

Severity
UNKNOWN
CVSS Score
0.0
Description

Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Real Estate Manager (Free) < 6.7.9 - site/realestatemanager.php builds the ORDER BY clause of three separate frontend property-listing queries (category browsing, search results, and the full property listing) from a request-controlled order_field parameter, concatenated directly into an unquoted SQL clause with no allow-list of real column names and no cast....

PoCs for CVE-CVE-2026-100752

CVE-2026-100752
SQL Injection Python 0
murrez 2026-09-29
Master Cybersecurity | Join CybersecPlayground for Cybersecurity Learning & Bug Bounty Resources