{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-88854","assignerOrgId":"6ff30186-7fb7-4ad9-be33-533e7b05e586","state":"PUBLISHED","assignerShortName":"Joomla","dateReserved":"2026-09-10T10:27:00.130Z","datePublished":"2026-09-20T17:53:02.886Z","dateUpdated":"2026-09-20T19:24:12.462Z"},"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","packageName":"com_osgallery_light","product":"OrdaSoft Joomla Gallery free extension for Joomla","vendor":"OrdaSoft.com","versions":[{"status":"affected","version":"1.0.0-6.2.6"}]},{"defaultStatus":"unaffected","packageName":"com_osgallery","product":"OrdaSoft Joomla Gallery extension for Joomla","vendor":"OrdaSoft.com","versions":[{"status":"affected","version":"1.0.0-6.2.6"}]}],"credits":[{"lang":"en","type":"finder","value":"Ala Arfaoui"}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"Joomla Extension - OrdaSoft.com - Unauthenticated SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions showSearchResult() and showSearchResultAjax() read the textsearch/searchText request parameter with $input->getVar(), which is not a real Joomla filter method and falls through to a filter that strips HTML tags but does not touch quotes or SQL syntax. The value is concatenated directly into a LIKE clause with no escaping. The endpoint requires no login of any kind: mod_osgallery_search is a public, commonly-published search box. Any anonymous site visitor can inject a UNION SELECT and read arbitrary database content."}],"value":"Joomla Extension - OrdaSoft.com - Unauthenticated SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions showSearchResult() and showSearchResultAjax() read the textsearch/searchText request parameter with $input->getVar(), which is not a real Joomla filter method and falls through to a filter that strips HTML tags but does not touch quotes or SQL syntax. The value is concatenated directly into a LIKE clause with no escaping. The endpoint requires no login of any kind: mod_osgallery_search is a public, commonly-published search box. Any anonymous site visitor can inject a UNION SELECT and read arbitrary database content."}],"metrics":[{"cvssV4_0":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":9.3,"baseSeverity":"CRITICAL","exploitMaturity":"NOT_DEFINED","privilegesRequired":"NONE","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnerabilityResponseEffort":"NOT_DEFINED"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-89","description":"CWE-89: Improper Neutralization of Special Elements used in an SQL Command","lang":"en","type":"CWE"}]}],"providerMetadata":{"orgId":"6ff30186-7fb7-4ad9-be33-533e7b05e586","shortName":"Joomla","dateUpdated":"2026-09-20T19:24:12.462Z"},"references":[{"tags":["product"],"url":"https://www.OrdaSoft.com/"}],"source":{"discovery":"UNKNOWN"},"title":"Joomla Extension - OrdaSoft.com - Unauthenticated SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7","x_generator":{"engine":"Vulnogram 0.1.0-dev"}}}}