Detects Joomla instances running versions 4.0.0–5.4.3 or 6.0.0–6.0.3 where the REST API articles endpoint (/api/index.php/v1/content/articles) passes user-supplied list[ordering] parameters directly into SQL ORDER BY clauses. The API controller bypasses the model's normal ordering validation, allowing any authenticated API user to inject SQL expressions and extract database contents — admin credentials, session tokens, and configuration secrets. Update to Joomla 5.4.4 or 6.0.4.
Is your app exploitable through CVE-2026-21630?
Scan your domain free