SQL Injection Vulnerability in UP Plugin for Joomla by lomart.fr
CVE-2026-97162

8.3HIGH

Key Information:

Vendor

Lomart.fr

Vendor
CVE Published:
26 September 2026

What is CVE-2026-97162?

The UP plugin for Joomla, developed by lomart.fr, is subject to multiple SQL injection vulnerabilities affecting versions 5.0.0 to 6.0.29. These vulnerabilities can be exploited by attackers to manipulate SQL queries, potentially allowing unauthorized access to sensitive data, compromise databases, and achieve overall system integrity exposure. It is essential for users to upgrade their plugin to the latest version to mitigate these security risks.

Affected Version(s)

UP plugin for Joomla 5.0.0-5.2.0

UP plugin for Joomla 6.0.0-6.0.29

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Phil Taylor, mysites.guru
.