Answer in brief
CVE-2026-102781 records a Medium severity (CVSS 6.9) vulnerability in Joomla Extension - ordasoft.com - Unauthenticated Destructive CRUD in OrdaSoft Touch Slider < 5.4.6. The current sources do not mark it as known exploited. The current feed maps ordasoft.com/Touch Slider extension for Joomla (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 6.9. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps ordasoft.com/Touch Slider extension for Joomla (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| ordasoft.com/Touch Slider extension for Joomlageneric | 1.0.0-5.4.5 | Not reported |
Published upstream
Oct 7, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 7, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 7, 2026
Joomla Extension - ordasoft.com - Unauthenticated Destructive CRUD in OrdaSoft Touch Slider < 5.4.6 - modOsTouchSliderHelper::getAjax(), wired through Joomla’s core com_ajax dispatcher, is the single handler behind every data-management operation this module exposes. No call to JFactory::getUser(), authorise(), or a CSRF token check exists anywhere in the handler. Two confirmed impact paths: an unauthenticated GET deletes any slider image by guessable sequential IDs, and an unauthenticated multipart upload with a zip file renames and replaces the entire #__os_touch_slider/#__os_touch_slider_text tables site-wide with attacker-supplied content, with no task parameter even required for the second path.
Quoted source text, attributed separately from HOL analysis.