Threat intelligence dashboard
CVE-2026-101109medium

Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Vehicle Manager (Free) < 6.5.8

Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Vehicle Manager (Free) < 6.5.8 - The public vehicle-detail page (task=view) echoes the title request parameter directly into a double-quoted HTML attribute with no output encoding of any kind. A double-quote character in the parameter closes the attribute, allowing arbitrary markup, including a <script> tag, to be injected into the page.

Risk score

5.3

CVSS 4.0

Vendor
ordasoft.com
Product
Vehicle Manager (Free) extension for Joomla
CWE
CWE-79
Published
Sep 28, 2026
Updated
Sep 28, 2026
CISA KEV
Not flagged

Affected products and versions

Vehicle Manager (Free) extension for Joomla

ordasoft.com

Version / rangeStatusType
1.0.0-6.5.7affected—

Technical metrics

5.3

CVSS 4.0

Severity
medium
Source
Joomla
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N