Junglewise Threat Intelligence

CVE-2026-88855: OrdaSoft Joomla Gallery SQL injection

CVE-2026-88855 · Severity: info · Published 2026-09-20

Technologies: OrdaSoft Joomla Gallery. Vendors: OrdaSoft.

Executive brief

OrdaSoft Joomla Gallery is a component for managing image galleries within Joomla websites. An authenticated user with gallery management permissions can inject SQL commands through unsanitized form fields, allowing them to read and modify database contents including user credentials and password hashes. This requires the attacker to already have legitimate gallery management access, significantly limiting the attack surface.

Technical details

The saveGallery() method in the extension parses form input and passes values from category_names[], catOrderIds, and image-ordering fields directly into SQL queries without quoting or type casting. An authenticated user with core.manage permission on the gallery component can exploit this via UNION-based SQL injection to extract sensitive data. The vulnerability requires prior authentication and scoped gallery management privileges, not administrator-level access.

Affected products

  • OrdaSoft Joomla Gallery < 6.2.7

Timeline

  • 2026-09-20: disclosed

References

Related threats