Unauthenticated SQL Injection Vulnerability in YouTube Gallery Extension by Joomla
CVE-2026-94130
9.3CRITICAL
What is CVE-2026-94130?
An SQL injection vulnerability in the YouTube Gallery extension for Joomla allows unauthenticated attackers to execute arbitrary SQL commands through the video search and sorting functionalities. This security flaw affects versions of the extension prior to 5.7.3, enabling potential exposure of sensitive data and manipulation of the database.
Affected Version(s)
YouTube Gallery extension for Joomla 1.0.0-5.7.2
References
CVSS V4
Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Osman Hussein
Krzysztof ZajÄ…c, CERT PL
Dick Snel, onvio.nl
