CVE-2026-49048

CVE-2026-49048CVE-2026-49048

Description

The Joomla extension JoomCCK exposes a front-end controller task, that builds two SQL statements by directly concatenating a user-supplied request parameter into the query string without escaping or parameterisation.

Scoring

Last modified2026-06-28
Sourced from NVD. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.