Junglewise Threat Intelligence

CVE-2026-78072: Joomla Sexy Polling Reloaded unauthenticated blind SQL injection

CVE-2026-78072 · Severity: info · Published 2026-08-28

Executive brief

Sexy Polling Reloaded is a Joomla extension that allows site administrators to create and manage polls with customizable voting options. An unauthenticated attacker can exploit a blind SQL injection vulnerability to extract sensitive data from the database without requiring a login, potentially compromising user information, poll data, and other database contents.

Technical details

The vulnerability is a blind SQL injection flaw in Sexy Polling Reloaded versions prior to 5.6.1 that allows unauthenticated attackers to execute arbitrary SQL queries. The vulnerable component does not properly sanitize or parameterize database queries, allowing attacker-controlled input to be included directly in SQL statements. The attack vector is network-based with no authentication required, making it exploitable by remote actors. Through blind SQL injection techniques, an attacker can infer database structure and exfiltrate data over time. Upgrading to version 5.6.1 or later is required to fix this vulnerability.

Affected products

  • Jefferson49 Sexy Polling Reloaded < 5.6.1

Timeline

  • 2026-08-28: disclosed: CVE-2026-78072 published

References