CRITICAL 9.3 NVD

CVE-2026-88854

Joomla Extension - OrdaSoft.com - Unauthenticated SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions showSearchResult() and

Joomla Extension - OrdaSoft.com - Unauthenticated SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions showSearchResult() and showSearchResultAjax() read the textsearch/searchText request parameter with $input->getVar(), which is not a real Joomla filter method and falls through to a filter that strips HTML tags but does not touch quotes or SQL syntax. The value is concatenated directly into a LIKE clause with no escaping. The endpoint requires no login of any kind: mod_osgallery_search is a public, commonly-published search box. Any anonymous site visitor can inject a UNION SELECT and read arbitrary database content.

References

Published: 2026-09-20 · Source: NVD · Feed updated: 2026-09-20
This critical severity vulnerability with a CVSS score of 9.3 was published on 2026-09-20 via NVD.

Risk Timeline

CVE Disclosed2026-09-20 · -1 days ago

Remediation Resources

Analysis & PoC
www.OrdaSoft.com/
vulnfeed aggregates 14834 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.