CVE-2026-101110 is an unauthenticated SQL-injection vulnerability in OrdaSoft Book Library (Free) for Joomla versions prior to 6.4.6. The extension's books() function processes attacker-controlled field and direction request parameters using a blacklist-based routine, then concatenates the resulting values into an unquoted SQL ORDER BY clause. The routine attempts to quote values only when it detects the literal substring "select" rather than rejecting malicious input; this does not secure the affected SQL context. Exploitation requires an initial request that primes session-stored sort defaults and a trailing decoy comment that triggers the blacklist condition without changing the injected query's effect.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This six-file repository is a standalone Python 3 exploit utility for CVE-2026-101110 affecting OrdaSoft Book Library (Free), Joomla component com_booklibrary, through version 6.4.6. Its sole code file, poc.py, uses requests and urllib3 to fingerprint accessible Book Library paths, discover viable Joomla routes and category/item identifiers, optionally retrieve an exposed extension manifest, and issue GET requests with POST fallback. It targets the field and direction sorting parameters in public listing tasks. The exploit first sends a benign request to establish session-stored sort defaults, then injects an ORDER BY expression followed by the '-- xselect' blacklist-bypass comment. Check mode detects SQL errors and can attempt a version leak; exploit mode performs error-based extraction of a configurable SQL subquery. Bulk modes accept a target list, run concurrently, generate JSONL records, and write candidate or successfully exploited targets to local files. Supporting files are a README with vulnerability and usage documentation, requirements.txt listing requests and urllib3, an example target list, license, and gitignore. This is an operational exploitation tool rather than a detection-only script because it actively extracts database query output from unauthenticated remote targets.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An unauthenticated SQL injection vulnerability in the OrdaSoft Book Library (Free) Joomla extension before version 6.4.6. User-controlled field and direction parameters are concatenated into an unquoted ORDER BY clause. Its keyword-blacklist-based filter can be bypassed using a trailing decoy comment containing "select," after priming session-stored sort defaults.
An unauthenticated SQL injection vulnerability in OrdaSoft Book Library (Free) versions before 6.4.6 for Joomla. Attacker-controlled field and direction request parameters reach an unquoted SQL ORDER BY clause after ineffective blacklist-based filtering. Exploitation requires priming session-stored sort defaults and appending a decoy comment that triggers the filter's substring check.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.