Unauthenticated SQL Injection in JooDatabase Lite by Feenders
CVE-2026-78080

9.3CRITICAL

Key Information:

Vendor
CVE Published:
3 September 2026

What is CVE-2026-78080?

The JooDatabase Lite extension by Feenders is susceptible to an unauthenticated SQL injection vulnerability due to insufficient validation of the cid parameter in queries. This flaw could allow attackers to manipulate and execute arbitrary SQL commands, potentially compromising the integrity and confidentiality of the database.

Affected Version(s)

JooDatabase Lite extension for Joomla 1.0-5.0.0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Krzysztof ZajÄ…c, CERT PL
.