{"id":"CVE-2026-88854","title":"Joomla Extension - OrdaSoft.com - Unauthenticated SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions showSearchResult() and showSearchResultAjax() read the textsearch/searchText request parameter with …","summary":"Joomla Extension - OrdaSoft.com - Unauthenticated SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions showSearchResult() and showSearchResultAjax() read the textsearch/searchText request parameter with …","severity":"critical","cvss":9.3,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","cwe":["CWE-89"],"vendor":"OrdaSoft.com","product":"com_osgallery_light","affected":["com_osgallery_light 1.0.0-6.2.6","com_osgallery 1.0.0-6.2.6"],"published":"2026-09-20","updated":"2026-09-21","sourceUpdated":"2026-09-21T15:17:34.187","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-88854","references":[{"url":"https://www.OrdaSoft.com/","label":"security@joomla.org"}],"tags":["nvd","exploit-available","cve.org"],"epss":0.00344,"epssPercentile":0.27901,"exploits":{"github":1,"githubRepos":["https://github.com/murrez/CVE-2026-88854"],"checkedAt":"2026-09-21T16:12:21.604Z"},"exploitAvailable":true,"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"total","timestamp":"2026-09-21T14:04:33.268540Z"},"cvssSource":"cna","ingestedAt":"2026-09-20T18:24:59.756Z","slug":"CVE-2026-88854","body":"## Overview\n\nJoomla Extension - OrdaSoft.com - Unauthenticated SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions showSearchResult() and showSearchResultAjax() read the textsearch/searchText request parameter with $input->getVar(), which is not a real Joomla filter method and falls through to a filter that strips HTML tags but does not touch quotes or SQL syntax. The value is concatenated directly into a LIKE clause with no escaping. The endpoint requires no login of any kind: mod_osgallery_search is a public, commonly-published search box. Any anonymous site visitor can inject a UNION SELECT and read arbitrary database content.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"abyssal","depthScore":63,"depthScoreParts":{"impact":51.2,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[{"seq":208512,"id":"CVE-2026-88854","ts":1790007417687,"field":"exploit_available","old":"false","new":"true"}]}