Unauthenticated SQL Injection Vulnerability in Joomla Extension by Joomcode
CVE-2026-76570
10CRITICAL
What is CVE-2026-76570?
The JCTables extension for Joomla is susceptible to an unauthenticated SQL injection vulnerability due to insufficient validation of user inputs in the front-end CRUD API controller. This flaw enables attackers to execute unauthorized SQL queries for both reading and writing data, as the input parameters for table names, column names, and values are directly incorporated into query strings without proper authentication or Joomla token validation.
Affected Version(s)
JCTables extension for Joomla 1.0.0-1.20.0
