Unauthenticated SQL Injection Vulnerability in YouTube Gallery Extension by Joomla
CVE-2026-94130

9.3CRITICAL

Key Information:

Vendor
CVE Published:
26 September 2026

What is CVE-2026-94130?

An SQL injection vulnerability in the YouTube Gallery extension for Joomla allows unauthenticated attackers to execute arbitrary SQL commands through the video search and sorting functionalities. This security flaw affects versions of the extension prior to 5.7.3, enabling potential exposure of sensitive data and manipulation of the database.

Affected Version(s)

YouTube Gallery extension for Joomla 1.0.0-5.7.2

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Osman Hussein
Krzysztof ZajÄ…c, CERT PL
Dick Snel, onvio.nl
.