ZeroHour

CVE-2026-78072

niche

Unauthenticated blind SQL injection in Joomla Sexy Polling Reloaded extension

CVSS 4.0
8.7 high
EPSS
<1%p25
Published
()
Modified
AI analysis

Sexy Polling Reloaded, a polling component for Joomla by developer Jefferson49, contains an unauthenticated blind SQL injection flaw (CWE-89) in versions prior to 5.6.1. An attacker can trigger it by sending crafted input to the extension's publicly accessible polling functionality without any credentials; the flaw is blind, so results are inferred indirectly rather than returned directly in responses. Successful exploitation yields high-impact read access to the site's database per the CVSS 4.0 score, potentially exposing sensitive data such as user records or credentials depending on database contents. Any Joomla site running a version of the extension below 5.6.1 is affected. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known, and EPSS estimates only a 0.3% probability of exploitation within 30 days.

What to do: Update Sexy Polling Reloaded to version 5.6.1 or later. If upgrading is not immediately possible, restrict unauthenticated access to the component where feasible (for example via WAF or web-server rules) and review web server and database logs for unusual query patterns or slow responses, which are typical signs of blind SQL injection probing.

Affected
Jefferson49 Sexy Polling Reloaded (Joomla extension)All versions prior to 5.6.1
Estimated exposure
nichelikely hundreds to low thousands of Joomla sites (niche polling extension; no published active-install count) — No active-install figures are published for this extension in the available data, so the estimate relies on deployment patterns: it is a niche Joomla polling component, meaning only a small subset of Joomla sites would have it installed…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Joomla Extension - Jefferson49 - Unauthenticated blind SQLi in Sexy Polling Reloaded < 5.6.1

Ecosystems
Joomla
Weakness
CWE-89
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.