CVE-2026-49048 is a SQL injection vulnerability in the Joomla extension JoomCCK. According to the provided content, a front-end controller task constructs two SQL statements by directly concatenating a user-supplied request parameter into the query string without escaping or parameterization. This unsafe query construction allows attacker-controlled input to alter the intended SQL logic executed by the application against the backend database.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone disclosure and PoC package for CVE-2026-49048, an unauthenticated SQL injection in JoomCCK com_joomcck 6.4.0. The structure is simple: README.md contains the advisory, root-cause analysis, exploitation examples, impact, and remediation; disclosure/timeline.md records the disclosure process; poc/poc-evidence.txt contains captured output from successful exploitation; and poc/poc.php is the only code file and serves as the main entry point. The exploit capability centers on the public Joomla endpoint /index.php?option=com_joomcck&task=tags.save, where the tag parameter is concatenated directly into SQL in the component's _saveTag() logic. The repository explains that a separate authorization flaw in the custom dispatcher allows unauthenticated access to this task. The PoC demonstrates three practical SQLi modes: quote breakout/boolean manipulation, UNION-based data exfiltration from jos_users, and time-based blind SQLi using SLEEP(). It also notes that the same unsafely concatenated input reaches an UPDATE query, so row modification is possible in addition to read access. The PHP PoC is not a remote exploit client against a live website; instead, it is an operational lab harness that recreates the vulnerable code path using real Joomla Input classes and a live local MariaDB instance. It connects to 127.0.0.1 using mysqli, builds the exact vulnerable SQL string, executes several hardcoded payloads, and prints returned rows and timing. This makes the repository a valid exploit/verification PoC rather than a mere detector. The README additionally documents other exposed unauthenticated tasks such as tags.delete, records.copy, ajax.category_records, ajax.tags_list, ajax.users_filter, and ajax.loadfieldparams, but the primary exploit focus is the SQL injection in task=tags.save.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.