SQL Injection Vulnerability in Joomla's com_finder Component
CVE-2026-35221

6.9MEDIUM

Key Information:

Vendor

Joomla

Vendor
CVE Published:
26 May 2026

What is CVE-2026-35221?

A SQL injection vulnerability has been identified in Joomla's com_finder component due to improperly constructed filter clauses. This flaw allows attackers to manipulate the search query, potentially leading to unauthorized access to sensitive data stored in the database. Website operators using affected versions of com_finder should apply the recommended security updates immediately to mitigate risks and ensure the protection of their systems. For further details, visit the Joomla Security Advisory.

Affected Version(s)

Joomla! CMS 6.0.0-6.1.0

Joomla! CMS 5.4.0-5.4.5

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Adrian Junge aka vurlo
.