Junglewise Threat Intelligence

CVE-2026-78080: Joomla JooDatabase unauthenticated SQL injection in cid parameter

CVE-2026-78080 · Severity: info · Published 2026-09-03

Executive brief

JooDatabase is a Joomla extension that allows administrators to display external database tables within Joomla sites. An unauthenticated SQL injection vulnerability in versions before 5.1.0 allows attackers to execute arbitrary SQL queries by manipulating the cid parameter, potentially leading to unauthorized data access, modification, or deletion of database contents.

Technical details

The vulnerability is a classic SQL injection flaw where the cid parameter is incorporated into database queries without proper input validation or parameterized statements. The vulnerability is unauthenticated, meaning no valid user credentials are required to exploit it. An attacker can craft malicious SQL statements in the cid parameter to extract sensitive data, modify records, or potentially execute administrative actions on the database. The fix is available in JooDatabase version 5.1.0 and later, where input validation and parameterized queries have been implemented.

Affected products

  • Feenders JooDatabase before 5.1.0

Timeline

  • 2026-09-03: disclosed

References