CRITICAL 9.4 NVD

CVE-2026-88857

Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions saveW

Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions saveWatermark() copied an uploaded file into a web-accessible directory using the client-supplied filename exactly as sent, with no extension check, no content check, and no filename sanitisation of any kind. An authenticated core.manage user could upload a .php file disguised with an image Content-Type header and execute it directly by requesting the resulting path.

References

Published: 2026-09-20 · Source: NVD · Feed updated: 2026-09-20
This critical severity vulnerability with a CVSS score of 9.4 was published on 2026-09-20 via NVD.

Risk Timeline

CVE Disclosed2026-09-20 · -1 days ago

Remediation Resources

Analysis & PoC
www.OrdaSoft.com/
vulnfeed aggregates 14834 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.