Description
Joomla Extension - OrdaSoft.com - Unauthenticated SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions showSearchResult() and showSearchResultAjax() read the textsearch/searchText request parameter with $input->getVar(), which is not a real Joomla filter method and falls through to a filter that strips HTML tags but does not touch quotes or SQL syntax. The value is concatenated directly into a LIKE clause with no escaping. The endpoint requires no login of any kind: mod_osgallery_search is a public, commonly-published search box. Any anonymous site visitor can inject a UNION SELECT and read arbitrary database content.
Published: 2026-09-20
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Data Theft via Unauthenticated SQL Injection
Action: Apply Patch
AI Analysis

Impact

A SQL injection flaw exists in the mod_osgallery_search component where the searchText request parameter is read with an insufficient Joomla filter, allowing arbitrary SQL code to be embedded into a LIKE clause. Because the parameter is used without escaping, an attacker can inject a UNION SELECT and retrieve sensitive database information. The weakness falls under CWE-89, entailing a severe compromise of confidentiality.

Affected Systems

The vulnerability affects installations of the OrdaSoft Joomla Gallery extension for Joomla, both free and paid versions, on any Joomla instance running a version of the extension earlier than 6.2.7. Any site that has this extension deployed is potentially exposed.

Risk and Exploitability

With a CVSS score of 9.3, this flaw is deemed critical; the EPSS score is currently not available, and the vulnerability is not listed in the CISA KEV catalog. The endpoint is publicly accessible and requires no authentication, so an attacker merely needs to send a crafted request to the search box. Successful exploitation would enable unauthorized reading of arbitrary database tables, exposing user credentials, site content, and potentially other sensitive data. The combination of a public entry point and high severity underlines the urgent need for remediation.

Generated by OpenCVE AI on September 20, 2026 at 19:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Configure database and web application logging to detect and alert on anomalous UNION SELECT queries for monitoring
  • Upgrade the OrdaSoft Joomla Gallery extension to version 6.2.7 or later to address the vulnerability
  • Implement a Web Application Firewall or security plugin rule to block or sanitize UNION SELECT patterns and restrict access to the search endpoint.

Generated by OpenCVE AI on September 20, 2026 at 19:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
Link Providers
https://www.OrdaSoft.com/ cve-icon cve-icon
History

Mon, 21 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 21 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Ordasoft.com
Ordasoft.com ordasoft Joomla Gallery Extension For Joomla
Ordasoft.com ordasoft Joomla Gallery Free Extension For Joomla
Vendors & Products Ordasoft.com
Ordasoft.com ordasoft Joomla Gallery Extension For Joomla
Ordasoft.com ordasoft Joomla Gallery Free Extension For Joomla

Sun, 20 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Description Joomla Extension - OrdaSoft.com - Unauthenticated SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions showSearchResult() and showSearchResultAjax() read the textsearch/searchText request parameter with $input->getVar(), which is not a real Joomla filter method and falls through to a filter that strips HTML tags but does not touch quotes or SQL syntax. The value is concatenated directly into a LIKE clause with no escaping. The endpoint requires no login of any kind: mod_osgallery_search is a public, commonly-published search box. Any anonymous site visitor can inject a UNION SELECT and read arbitrary database content.
Title Joomla Extension - OrdaSoft.com - Unauthenticated SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7
Weaknesses CWE-89
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Ordasoft.com Ordasoft Joomla Gallery Extension For Joomla Ordasoft Joomla Gallery Free Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-09-22T04:46:40.480Z

Reserved: 2026-09-10T10:27:00.130Z

Link: CVE-2026-88854

cve-icon Vulnrichment

Updated: 2026-09-21T14:04:51.177Z

cve-icon NVD

Status : Deferred

Published: 2026-09-20T18:16:53.987

Modified: 2026-09-22T19:34:57.263

Link: CVE-2026-88854

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T10:02:15Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')