{"id":"CVE-2026-101111","published":"2026-09-28T19:16:47.387","lastModified":"2026-09-29T21:39:02.570","description":"Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Book Library (Free) < 6.4.6 - The public book-detail page template, site/views/view_book/tmpl/default.php, echoes the raw title request parameter directly into a double-quoted HTML attribute with no escaping function of any kind (echo $_REQUEST[\"title\"];). A value containing a double quote closes the attribute early and allows arbitrary HTML/JavaScript to follow.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":["CWE-79"],"vendors":[],"products":[],"references":[{"url":"https://www.ordasoft.com/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}