---
id: CVE-2017-20269
title: >-
  Joomla! Component KissGallery 1.0.0 contains an SQL injection vulnerability
  that allows unauthenticated attackers to inject SQL commands through the
  component URL path
summary: >-
  Joomla! Component KissGallery 1.0.0 contains an SQL injection vulnerability
  that allows unauthenticated attackers to inject SQL commands through the
  component URL path. Attackers can supply malicious SQL code in the kissgallery
  endpoint …
severity: high
cvss: 8.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'
cwe:
  - CWE-89
vendor: terrywcarter
product: kissgallery
affected:
  - kissgallery = 1.0.0
published: '2026-06-19'
updated: '2026-08-21'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2017-20269'
references:
  - url: 'http://terrywcarter.com/'
    label: disclosure@vulncheck.com
  - url: >-
      https://extensions.joomla.org/extensions/extension/photos-a-images/galleries/kissgallery/
    label: disclosure@vulncheck.com
  - url: 'https://www.exploit-db.com/exploits/42494'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/joomla-component-kissgallery-sql-injection
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00331
epssPercentile: 0.26384
ingestedAt: '2026-08-22T13:32:34.650Z'
---

## Overview

Joomla! Component KissGallery 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to inject SQL commands through the component URL path. Attackers can supply malicious SQL code in the kissgallery endpoint to execute arbitrary database queries and extract sensitive information.

## Affected

- `kissgallery = 1.0.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
