CVE-CVE-2026-88854
Severity
UNKNOWN
CVSS Score
0.0
Description
Joomla Extension - OrdaSoft.com - Unauthenticated SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions showSearchResult() and showSearchResultAjax() read the textsearch/searchText request parameter with $input->getVar(), which is not a real Joomla filter method and falls through to a filter that strips HTML tags but does not touch quotes or SQL syntax. The value is concatenated directly into a LIKE clause with no escaping. The endpoint requires no login of any k...
PoCs for CVE-CVE-2026-88854
CVE-2026-88854
SQL Injection
Python
0
murrez
2026-09-20