Unauthenticated SQL Injection in OrdaSoft Joomla Gallery Extension
CVE-2026-88854
9.3CRITICAL
What is CVE-2026-88854?
The OrdaSoft Joomla Gallery extension is vulnerable to an unauthenticated SQL injection attack. This flaw exists due to improper validation of the 'textsearch/searchText' parameter in the 'showSearchResult()' and 'showSearchResultAjax()' functions. Since this parameter is directly concatenated into a SQL query without proper escaping, any anonymous user can exploit this vulnerability via the public search box feature. This allows attackers to execute arbitrary SQL commands, potentially extracting sensitive data from the database. It is crucial for users to upgrade to version 6.2.7 or later to mitigate this risk.
Affected Version(s)
OrdaSoft Joomla Gallery extension for Joomla 1.0.0-6.2.6
OrdaSoft Joomla Gallery free extension for Joomla 1.0.0-6.2.6
