{"id":"CVE-2026-101109","published":"2026-09-28T19:16:47.083","lastModified":"2026-09-29T21:39:02.570","description":"Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Vehicle Manager (Free) < 6.5.8 - The public vehicle-detail page (task=view) echoes the title request parameter directly into a double-quoted HTML attribute with no output encoding of any kind. A double-quote character in the parameter closes the attribute, allowing arbitrary markup, including a <script> tag, to be injected into the page.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":["CWE-79"],"vendors":[],"products":[],"references":[{"url":"https://www.ordasoft.com/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}