SQL Injection Vulnerability in Joomla's com_finder Component
CVE-2026-35221
6.9MEDIUM
What is CVE-2026-35221?
A SQL injection vulnerability has been identified in Joomla's com_finder component due to improperly constructed filter clauses. This flaw allows attackers to manipulate the search query, potentially leading to unauthorized access to sensitive data stored in the database. Website operators using affected versions of com_finder should apply the recommended security updates immediately to mitigate risks and ensure the protection of their systems. For further details, visit the Joomla Security Advisory.
Affected Version(s)
Joomla! CMS 6.0.0-6.1.0
Joomla! CMS 5.4.0-5.4.5