CVE-2026-101109EPSS p16.4%
CVE-2026-101109CVE-2026-101109
Description
Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Vehicle Manager (Free) < 6.5.8 - The public vehicle-detail page (task=view) echoes the title request parameter directly into a double-quoted HTML attribute with no output encoding of any kind. A double-quote character in the parameter closes the attribute, allowing arbitrary markup, including a <script> tag, to be injected into the page.
Scoring
| EPSS | 0.26% probability of exploitation · percentile 16.4% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-30 |