VulnSea

OrdaSoft.com has 4 CVEs on record. 4 were published in the last 90 days. The busiest recent month was September 2026 with 4. The median CVSS is 9.4 (critical), with 3 rated critical.

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
9.4
Publish → KEV
Last 90 days
4 prev 0

Products

  • com_osgallery_light 4
4
Total CVEs
3
Critical
0
CISA KEV
0
Exploited

OrdaSoft.com vulnerabilities

CVEs affecting OrdaSoft.com, newest first. Open any entry for full detail, references, and exploit status.

4 CVEsRSS

CVE-2026-88857Critical· 9.4
yesterday

Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions saveWatermark() copied an uploaded file into a web-accessible directory using the …

Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions saveWatermark() copied an uploaded file into a web-accessible directory using the …

MidnightOrdaSoft.com · com_osgallery_lightEPSS 0.47%via NVD
CVE-2026-88856Critical· 9.4
yesterday

Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions updateOSGallery(), reached via task=update_osgallery, read a JSON request body and…

Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions updateOSGallery(), reached via task=update_osgallery, read a JSON request body and…

MidnightOrdaSoft.com · com_osgallery_lightEPSS 0.48%via NVD
CVE-2026-88855High· 8.6
yesterday

Joomla Extension - OrdaSoft.com - Authenticated, Privileged SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions saveGallery() passes form data through a hand-rolled parser into Joomla’s Input object, th…

Joomla Extension - OrdaSoft.com - Authenticated, Privileged SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions saveGallery() passes form data through a hand-rolled parser into Joomla’s Input object, th…

TwilightOrdaSoft.com · com_osgallery_lightEPSS 0.27%via NVD
CVE-2026-88854Critical· 9.3PoC
yesterday

Joomla Extension - OrdaSoft.com - Unauthenticated SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions showSearchResult() and showSearchResultAjax() read the textsearch/searchText request parameter with …

Joomla Extension - OrdaSoft.com - Unauthenticated SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions showSearchResult() and showSearchResultAjax() read the textsearch/searchText request parameter with …

AbyssalOrdaSoft.com · com_osgallery_lightEPSS 0.34%via NVD
OrdaSoft.com vulnerabilities (CVEs) · VulnSea