CVE-2026-94130: Joomla Extension - joomlaboat.com - Unauthenticated SQL injection in YouTube Gallery extension < 5.7.3
Published Sep 26, 2026
·Updated
Joomla Extension - joomlaboat.com - Unauthenticated SQL injection in YouTube Gallery extension < 5.7.3 - An SQL injection vulnerability in video search functionality and sorting allowed attackers to inject SQL commands in read queries.
Affected Software
1 affected component
joomlaboat.com YouTube Gallery<5.7.3
Event History
Sep 26, 2026
CVE Published
via MITRE·01:41 PM
Data Sourced
via MITRE·01:41 PM
DescriptionWeakness
Frequently Asked Questions
1
Which deployments are affected?
The issue affects joomlaboat.com YouTube Gallery extension versions earlier than 5.7.3.
2
Does exploitation require authentication?
No. The vulnerability is described as unauthenticated, so an attacker does not need to log in before targeting the affected video search and sorting functionality.
3
Which functionality is involved in the injection?
The affected paths are the extension's video search functionality and sorting behavior, where SQL commands could be injected into read queries.