Reflected Cross-Site Scripting in Joomla Extension by Ordasoft
CVE-2026-101111

5.3MEDIUM

Key Information:

Vendor
CVE Published:
28 September 2026

What is CVE-2026-101111?

A reflected Cross-Site Scripting (XSS) vulnerability exists in the Book Library extension developed by Ordasoft for Joomla platforms. Specifically, this issue arises in the public book-detail page template, where the application improperly handles user input by echoing the raw title request parameter directly into a double-quoted HTML attribute without any escaping. This misconfiguration allows attackers to craft a malicious URL that could execute arbitrary HTML or JavaScript code within the user's browser, potentially leading to data theft or unauthorized actions. Users of Book Library versions prior to 6.4.6 are advised to update their installations promptly to mitigate this risk.

Affected Version(s)

Book Library (Free) extension for Joomla 1.0.0-6.4.6

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ala Arfaoui
.