Junglewise Threat Intelligence

CVE-2026-97162: Joomla UP plugin SQL injection

CVE-2026-97162 · Severity: info · Published 2026-09-26

Executive brief

The UP plugin for Joomla contains multiple SQL injection vulnerabilities that allow attackers to directly access and manipulate the database. An attacker with network access could extract sensitive data, modify or delete database records, or potentially escalate privileges depending on database permissions. This affects plugin versions 5.0.0 through 5.2.0 and 6.0.0 through 6.0.29.

Technical details

Multiple SQL injection vulnerabilities exist in the UP plugin for Joomla across versions 5.0.0-5.2.0 and 6.0.0-6.0.29, allowing unauthenticated or authenticated attackers to inject arbitrary SQL through unfiltered user input. These vulnerabilities enable database query manipulation, potentially permitting unauthorized data access, modification, or deletion. Patches are expected in versions after 5.2.0 and 6.0.29.

Affected products

  • lomart.fr UP 5.0.0-5.2.0, 6.0.0-6.0.29

Timeline

  • 2026-09-26: disclosed

References

Related threats