PT-2026-95994 · Ordasoft · Ordasoft Joomla Gallery

·

CVE-2026-88854

·

Published

2026-09-20

·

Updated

2026-09-26

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions OrdaSoft Joomla Gallery versions prior to 6.2.7
Description An unauthenticated SQL Injection exists in the OrdaSoft Joomla Gallery extension. The functions showSearchResult() and showSearchResultAjax() process the textsearch or searchText request parameters using $input->getVar(), which fails to properly filter quotes or SQL syntax. This allows the input to be concatenated directly into a LIKE clause without escaping. Because the mod osgallery search endpoint is public and requires no authentication, an anonymous visitor can use a UNION SELECT statement to read arbitrary database content.
Recommendations Update to version 6.2.7 or later.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-88854

Affected Products

Ordasoft Joomla Gallery