Six confirmed Joomla extension vulnerabilities affect the Free editions of OrdaSoft Real Estate Manager, Vehicle Manager and Book Library. Site owners should update the first two extensions immediately and treat Book Library versions through 6.4.6 as vulnerable while waiting for an explicitly identified fixed release.
Administrators using the Free editions of OrdaSoft Real Estate Manager, Vehicle Manager or Book Library should review their installations promptly. The published records describe three unauthenticated SQL injection issues rated CVSS 4.0 9.3 CRITICAL and three reflected cross-site scripting issues rated CVSS 4.0 5.3 MEDIUM.
Confirmed Joomla Extension Vulnerabilities
Six published CVE records affect the Free editions of three OrdaSoft Joomla extensions. The confirmed set consists of three unauthenticated SQL injection vulnerabilities, classified as CWE-89, and three reflected cross-site scripting vulnerabilities, classified as CWE-79.
The SQL injection issues are CVE-2026-100752 in Real Estate Manager (Free), CVE-2026-101108 in Vehicle Manager (Free), and CVE-2026-101110 in Book Library (Free). Each has a CVSS 4.0 base score of 9.3 CRITICAL.
The reflected XSS issues are CVE-2026-100753 in Real Estate Manager (Free), CVE-2026-101109 in Vehicle Manager (Free), and CVE-2026-101111 in Book Library (Free). Each has a CVSS 4.0 base score of 5.3 MEDIUM.
All six records describe network-reachable conditions that do not require an authenticated Joomla account. The published CVE records specifically identify the Free editions. There is not sufficient authoritative evidence to state that OrdaSoft Pro or ShopPro editions are affected by these same CVEs.
Joomla Extension Vulnerabilities at a Glance
The following table summarises the confirmed affected ranges and the currently supportable remediation guidance. CVSS values shown are CVSS 4.0 base scores; they should not be compared as though they were scores from another CVSS version.
| Extension | CVE | Issue | Authentication | Affected versions | Recommended version | CVSS 4.0 | CISA KEV |
|---|---|---|---|---|---|---|---|
| Real Estate Manager (Free) | CVE-2026-100752 | SQL injection (CWE-89) | None | 1.0.0 through 6.7.8 | 6.7.9 or later | 9.3 CRITICAL | Not listed |
| Real Estate Manager (Free) | CVE-2026-100753 | Reflected XSS (CWE-79) | None | 1.0.0 through 6.7.8 | 6.7.9 or later | 5.3 MEDIUM | Not listed |
| Vehicle Manager (Free) | CVE-2026-101108 | SQL injection (CWE-89) | None | 1.0.0 through 6.5.7 | 6.5.8 or later | 9.3 CRITICAL | Not listed |
| Vehicle Manager (Free) | CVE-2026-101109 | Reflected XSS (CWE-79) | None | 1.0.0 through 6.5.7 | 6.5.8 or later | 5.3 MEDIUM | Not listed |
| Book Library (Free) | CVE-2026-101110 | SQL injection (CWE-89) | None | 1.0.0 through 6.4.6 | No clearly identified fixed version | 9.3 CRITICAL | Not listed |
| Book Library (Free) | CVE-2026-101111 | Reflected XSS (CWE-79) | None | 1.0.0 through 6.4.6 | No clearly identified fixed version | 5.3 MEDIUM | Not listed |
Why the SQL Injection Issues Need Priority Attention
SQL injection occurs when application input can alter the structure or logic of a database query rather than being handled solely as data. In these cases, the records describe attacker influence over sorting logic in public listing functions. Real Estate Manager is affected through an order_field parameter; Vehicle Manager through order_field and order_direction; and Book Library through field and direction.
Administrators do not need to test these conditions themselves. The operational concern is that a successful SQL injection attack can potentially expose or modify database contents and can affect the availability of a Joomla site. Because the three SQL injection vulnerabilities are described as unauthenticated and network-reachable, public-facing sites using affected versions deserve the highest remediation priority.
The severity ratings do not, by themselves, prove observed exploitation. They express the potential impact and exploitability characteristics assessed in the published CVSS 4.0 data. A CRITICAL score is a strong reason to patch promptly, but it is not a claim that a compromise has occurred.
What the Reflected XSS Issues Mean for Visitors
The three XSS records describe a title parameter being returned in a double-quoted HTML attribute without appropriate escaping. In a reflected XSS scenario, an attacker may attempt to persuade a visitor to open a crafted link to a vulnerable public page. If successful, malicious script could run in that visitor's browser in the context of the affected site.
This can place visitor sessions, displayed content and browser-based interactions at risk. The affected areas described in the records include a public property review form for Real Estate Manager, a public vehicle-detail page for Vehicle Manager, and a public book-detail page template for Book Library.
The XSS vulnerabilities are rated MEDIUM under CVSS 4.0, lower than the SQL injection findings, but they should be remediated through the same extension update process. Public-facing pages, logged-in staff users and administrative workflows all benefit from removing the vulnerable version rather than relying on visitor caution.
Prioritized Remediation for Joomla Administrators
Begin by establishing whether any production, staging, development, archived or client-managed Joomla site uses the affected Free extensions. An unused copy can still create exposure if it remains installed and its public component remains accessible.
- Inventory the extensions and versions. Check installed extensions and confirm whether Real Estate Manager (Free), Vehicle Manager (Free), or Book Library (Free) is present. Record the version on every site, not only the primary production domain.
- Update Real Estate Manager (Free). Upgrade versions through 6.7.8 to 6.7.9 or later. This addresses CVE-2026-100752 and CVE-2026-100753 according to the published affected range.
- Update Vehicle Manager (Free). Upgrade versions through 6.5.7 to 6.5.8 or later. This addresses CVE-2026-101108 and CVE-2026-101109.
- Contain Book Library (Free) exposure. Treat every Book Library (Free) version through and including 6.4.6 as vulnerable. If the component cannot be removed immediately, assess whether its public functionality can be disabled or restricted until a clearly identified fixed release is available.
- Remove leftovers. Delete or disable obsolete extension copies, test installations and duplicate Joomla deployments that remain reachable from the internet.
- Validate after change. Confirm the intended version is active, clear applicable caches, verify normal public functions, and ensure no old deployment path is still serving the prior code.
Take a tested backup before an update, but do not let a routine change-control process create unnecessary delay for the two products with published fixed-version guidance. Agencies should also notify clients whose hosting accounts may contain separate staging or legacy sites outside the normal maintenance inventory.
Book Library 6.4.6 Requires a Cautious Response
Book Library requires special care because the available version information is inconsistent. The CVE titles describe versions below 6.4.6, while the affected version range in both records lists versions 1.0.0 through 6.4.6 as affected. The records do not supply a clear excluded version that can safely be named as fixed.
For that reason, JoomlaForever's defensive guidance is to treat Book Library (Free) 6.4.6 as affected, not as a remediation target. Do not assume that installing or retaining 6.4.6 resolves CVE-2026-101110 or CVE-2026-101111. Monitor the vendor and the published CVE records for clarification of the fixed version, then schedule an upgrade as soon as authoritative guidance identifies one.
Where business requirements make the component essential, document the temporary exposure decision, reduce public access where practical, and increase monitoring until a confirmed fix can be deployed. This is a precautionary response to conflicting version data, not evidence of a separate vulnerability beyond the two published Book Library CVEs.
Monitoring and Temporary Defensive Controls
A patch is the primary remedy. Monitoring and web application firewall controls can provide useful defence in depth while updates are being scheduled, but they should not be treated as a substitute for replacing vulnerable code.
- Review web server, WAF and application-security alerts for unusual requests involving the affected public-page parameters: order_field, order_direction, field, direction and title.
- Investigate unexpected error increases, anomalous database activity, unusual response sizes, or repeated malformed requests to property, vehicle or book listing and detail functions.
- Review Joomla administrator accounts and extension configuration changes if suspicious activity is identified. Preserve relevant logs before rotation where your retention policy allows.
- Ensure database accounts used by Joomla have only the privileges required for the site. This is a general containment measure and does not replace updating the extension.
- Maintain separate inventories for customer sites, subdomains and staging systems so a completed production update does not hide an overlooked vulnerable instance.
A WAF rule may help identify suspicious traffic patterns, but broad blocking rules can also affect legitimate sorting or search features. Apply temporary controls carefully, test public functionality, and retain the update as the endpoint of the remediation process.
How to Interpret CVSS, NVD and CISA KEV Status
The current CVSS values in the CVE and NVD records are CVSS 4.0 scores: 9.3 CRITICAL for the SQL injection issues and 5.3 MEDIUM for the XSS issues. These are the current published ratings and may be updated as analysis progresses.
The National Vulnerability Database currently lists all six CVEs with a status of Received, meaning full NVD analysis is still pending. Administrators can rely on the published CVE records for the current affected-version and technical information while recognizing that NVD enrichment is not complete.
None of CVE-2026-100752, CVE-2026-100753, CVE-2026-101108, CVE-2026-101109, CVE-2026-101110 or CVE-2026-101111 is currently listed in the CISA Known Exploited Vulnerabilities catalog. There is also no authoritative confirmation in the available records that these issues are being exploited in the wild. That absence does not make affected installations safe; it means observed exploitation has not been confirmed by CISA or the available authoritative evidence.
Practical Next Steps
For Real Estate Manager (Free) and Vehicle Manager (Free), the action is clear: move to the published fixed version or a later version, then remove older copies. For Book Library (Free), assume versions through 6.4.6 remain affected, reduce exposure where possible, and watch for a vendor or CVE update that explicitly identifies a fixed release.
Keep the scope precise. The confirmed records cover the Free editions named in this advisory. Avoid extending the finding to other editions without a current vendor advisory or updated CVE record. A disciplined inventory, prompt updates, removal of stale instances and focused monitoring are the appropriate response to these Joomla extension vulnerabilities.
Add comment