Ordasoft develops a focused suite of Joomla extensions for e-commerce and content management, including components for book libraries, real-estate listings, vehicle management, and advertising, deployed across modestly sized web properties. Its vulnerability profile skews toward serious outcomes with elevated critical severity, and the recurring issues center on code injection and SQL injection in user input handling, weaknesses common to web extensions that directly process untrusted data from forms and URLs. Defenders should treat updates to these components as priority patches for any Joomla installation running them; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ordasoft over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-5971CRITICAL SQL Injection exists in the MediaLibrary Free 4.0.12 component for Joomla! via the id parameter or the mid array parameter. | Feb 17, 2018 | 9.8 | 42 | NO | YES |
CVE-2018-5982CRITICAL SQL Injection exists in the Advertisement Board 3.1.0 component for Joomla! via a task=show_rss_categories&catname= request. | Feb 17, 2018 | 9.8 | 40 | NO | YES |
CVE-2009-2637HIGH PHP remote file inclusion vulnerability in toolbar_ext.php in the BookLibrary (com_booklibrary) component 1.5.2.4 Basic for Joomla! allows remote attackers to execute arbitrary PHP | Jul 28, 2009 | 7.5 | 30 | NO | YES |
CVE-2009-3817HIGH PHP remote file inclusion vulnerability in doc/releasenote.php in the BookLibrary (com_booklibrary) component 1.0 for Joomla! allows remote attackers to execute arbitrary PHP code | Oct 28, 2009 | 7.5 | 28 | NO | YES |
CVE-2009-2635HIGH PHP remote file inclusion vulnerability in toolbar_ext.php in the RealEstateManager (com_realestatemanager) component 1.0 Basic for Joomla! allows remote attackers to execute arbit | Jul 28, 2009 | 7.5 | 28 | NO | YES |
CVE-2009-2634HIGH PHP remote file inclusion vulnerability in toolbar_ext.php in the MediaLibrary (com_media_library) component 1.5.3 Basic for Joomla! allows remote attackers to execute arbitrary PH | Jul 28, 2009 | 7.5 | 28 | NO | YES |
CVE-2009-2633HIGH PHP remote file inclusion vulnerability in toolbar_ext.php in the VehicleManager (com_vehiclemanager) component 1.0 Basic for Joomla! allows remote attackers to execute arbitrary P | Jul 28, 2009 | 7.5 | 28 | NO | YES |
CVE-2010-2851HIGH SQL injection vulnerability in the BookLibrary From Same Author (com_booklibrary) module 1.5 and possibly earlier for Joomla! allows remote attackers to execute arbitrary SQL comma | Jul 25, 2010 | 7.5 | 22 | NO | NO |
CVE-2010-1522HIGH Multiple SQL injection vulnerabilities in the BookLibrary Basic (com_booklibrary) component 1.5.3 before 1.5.3_2010_06_20 for Joomla! allow remote attackers to execute arbitrary SQ | Jul 2, 2010 | 7.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ordasoft.
Media articles that mention a CVE ID that affects a product developed by Ordasoft — matched by CVE ID, not by vendor name.