CVE-2026-88855 – Joomla Extension – OrdaSoft.com – Unauthenticated SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7

​CVE ID :CVE-2026-88855

Published : Sept. 20, 2026, 6:16 p.m. | 25 minutes ago

Description :Joomla Extension – OrdaSoft.com – Authenticated, Privileged SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 – The extensions saveGallery() passes form data through a hand-rolled parser into Joomla’s Input object, then reads it back with the ARRAY/ STRING filter types, neither of which sanitises SQL content. Values from category_names[], catOrderIds, and image-ordering fields were concatenated directly into SQL with no quoting or integer cast, giving an authenticated core.manage user (a permission scoped to managing one gallery component, not administrator-wide trust) full read/write access to the database, including UNION-based extraction of #__users password hashes.

Severity: 8.6 | HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more… To Read More Visit Read More