Description
Joomla Extension - Jefferson49 - Unauthenticated blind SQLi in Sexy Polling Reloaded < 5.6.1
Published: 2026-08-28
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A blind SQL injection flaw permits unauthenticated attackers to construct and execute arbitrary SQL statements against the database. Because the injection is blind, attackers can infer database structure and data by timing or error differences, potentially exfiltrating sensitive information or corrupting data. This weakness is a classic example of CWE‑89 and can have serious consequences for confidentiality and integrity of site data.

Affected Systems

The flaw is present in the Jefferson49 Sexy Polling Reloaded extension for Joomla, affecting all installations running a version earlier than 5.6.1. Joomla sites leveraging this plugin without an updated component are therefore exposed.

Risk and Exploitability

The CVSS score of 8.7 indicates high impact and overall potential. The EPSS score is not available, so the likelihood of exploitation cannot be quantified, but the lack of an authentication requirement and blind SQL injection typically facilitate automated attacks. The vulnerability is not listed in CISA’s KEV catalog, but its high severity warrants prompt attention. Based on the description, the attack vector is likely through web parameters exposed by the extension, where an attacker can submit crafted input without any pre‑existing credentials.

Generated by OpenCVE AI on August 28, 2026 at 14:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor-published patch by upgrading the Sexy Polling Reloaded extension to version 5.6.1 or later.
  • If an upgrade is not immediately possible, disable or uninstall the Sexy Polling Reloaded extension to eliminate the attack surface.
  • Reconfigure database user privileges to the minimum necessary permissions and consider using a Web Application Firewall to block suspicious SQL patterns.

Generated by OpenCVE AI on August 28, 2026 at 14:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Jefferson49
Jefferson49 sexy Polling Reloaded Extension For Joomla
Vendors & Products Jefferson49
Jefferson49 sexy Polling Reloaded Extension For Joomla

Fri, 28 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 28 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
Description Joomla Extension - Jefferson49 - Unauthenticated blind SQLi in Sexy Polling Reloaded < 5.6.1
Title Joomla Extension - Jefferson49 - Unauthenticated blind SQLi in Sexy Polling Reloaded < 5.6.1
Weaknesses CWE-89
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Jefferson49 Sexy Polling Reloaded Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-08-28T15:09:17.404Z

Reserved: 2026-08-22T14:23:37.800Z

Link: CVE-2026-78072

cve-icon Vulnrichment

Updated: 2026-08-28T15:09:12.514Z

cve-icon NVD

Status : Deferred

Published: 2026-08-28T12:16:31.957

Modified: 2026-08-28T16:18:27.157

Link: CVE-2026-78072

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T16:12:43Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')