CVE-2026-88854

LOWCVSS 9.3 · CRITICAL

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Joomla Extension - OrdaSoft.com - Unauthenticated SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions showSearchResult() and showSearchResultAjax() read the textsearch/searchText request parameter with $input->getVar(), which is not a real Joomla filter method and falls through to a filter that strips HTML tags but does not touch quotes or SQL syntax. The value is concatenated directly into a LIKE clause with no escaping. The endpoint requires no login of any kind: mod_osgallery_search is a public, commonly-published search box. Any anonymous site visitor can inject a UNION SELECT and read arbitrary database content.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 4 mentions across 1 observed day

What's happening

  • 4 total mentions across 1 day

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-09-20: 409-20
Referenced assets4 URLs
Full discourse4 posts
  • Rıdvan Yağlı@ridvanyagli

    🔴 CVE-2026-88854 — OrdaSoft Joomla Gallery'de kritik SQL Injection açığı için PoC yayınlandı. OrdaSoft OS Responsive Image Gallery 1.0.0–6.2.6 sürümlerini etkileyen açık, kimlik doğrulaması gerektirmeden SQL sorgularının manipüle edilmesine ve uygun koşullarda veritabanı içeriğinin okunmasına izin verebiliyor. CVSS: 9.3 Critical. Yamalanmış sürüm: 6.2.7+ PoC: https://github.com/murrez/CVE-2026-88854

    02042477
    2.3K followersView on X
  • mürrez@murrezsec

    CVE-2026-88854 (CVSS 9.3) — unauthenticated SQLi in OrdaSoft Joomla Gallery (com_osgallery ≤ 6.2.6). Public image search: showSearchResultAjax + textsearch → unsanitized LIKE concat. PoC: check / mass scan 🔗 https://github.com/murrez/CVE-2026-88854 Authorized testing only.

    0002051
    601 followersView on X
  • CVE@CVEnew

    CVE-2026-88854 Joomla Extension - https://OrdaSoft.com - Unauthenticated SQL Injection in OrdaSoft Joomla Gallery extension for Joomla &lt; 6.2.7 - The extensions showSearchResult() and showSe… https://www.cve.org/CVERecord?id=CVE-2026-88854

    00000724
    58.1K followersView on X
  • Severity Daily@severitydaily

    Two OrdaSoft Joomla Gallery SQL injections are both titled "Unauthenticated." Only one is — a 9.3 anyone can reach from a public search box. The other's own vector says it needs a login. No exploitation reported. https://severitydaily.com/ordasoft-joomla-gallery-cve-2026-88854-88855-titled-unauthenticated-only-one-is/

    0000025
    24 followersView on X

Explore more