CRITICAL 10.0 NVD
CVE-2026-76570
Joomla Extension - joomcode.com - Unauthenticated SQL injection in read and write queries in JCTables 1.21.1 - The front-end CRUD API controller performs no Jo
Joomla Extension - joomcode.com - Unauthenticated SQL injection in read and write queries in JCTables 1.21.1 - The front-end CRUD API controller performs no Joomla token validation and no authentication check on any task. Table names, column names, and values are taken directly from request parameters and concatenated into SQL queries, allowing SQLi for reading and writing queries.
References
This critical severity vulnerability with a CVSS score of 10.0 was published on 2026-09-30 via NVD.
Risk Timeline
CVE Disclosed2026-09-30 · -1 days ago
Remediation Resources
Official Advisory
www.vulncheck.com/blog/jctables-unauthenticated-sql-rw-to-rceAnalysis & PoC
www.joomcode.com/
vulnfeed aggregates 9504 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.