CVE-2026-88854: Joomla Extension - OrdaSoft.com - Unauthenticated SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7

Published Sep 20, 2026
·
Updated

Joomla Extension - OrdaSoft.com - Unauthenticated SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions showSearchResult() and showSearchResultAjax() read the textsearch/searchText request parameter with $input->getVar(), which is not a real Joomla filter method and falls through to a filter that strips HTML tags but does not touch quotes or SQL syntax. The value is concatenated directly into a LIKE clause with no escaping. The endpoint requires no login of any kind: modosgallerysearch is a public, commonly-published search box. Any anonymous site visitor can inject a UNION SELECT and read arbitrary database content.

Affected Software

1 affected component
Joomla Gallery extension<6.2.7

Event History

Sep 20, 2026
CVE Published
via MITRE·05:53 PM
Data Sourced
via MITRE·05:53 PM
DescriptionWeakness

Frequently Asked Questions

1

Who can exploit this issue?

Any anonymous visitor can exploit it if the mod_osgallery_search search box is publicly published. No login or other authentication is required.

2

What does an attacker need to send?

An attacker needs to supply SQL syntax in the textsearch or searchText request parameter handled by showSearchResult() or showSearchResultAjax(). Because the value is inserted directly into a LIKE clause without escaping, a UNION SELECT can be used to read arbitrary database content.

3

Which versions are affected?

The issue affects OrdaSoft Joomla Gallery extension versions earlier than 6.2.7.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203