External risk intelligence

Joomla OrdaSoft Gallery SQL Injection

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-88854

The vulnerability exists in a public-facing search module for a Joomla extension. The search functionality is designed to be accessible to any anonymous site visitor without authentication, making the attack surface directly reachable via the public internet as part of normal site usage.

SQL Injection

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability affects a Joomla extension's search functionality, allowing unauthenticated attackers to inject SQL commands and potentially access or modify sensitive database content. The primary concern is to confirm if this specific extension is in use and if so, assess exposure.

  • Unauthenticated search can expose database contents.
  • Critical for confirming use of a specific Joomla extension.
  • Verify use and assess potential data exposure.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by submitting a crafted search request through a public Joomla gallery search box. The extension's search feature fails to properly sanitize user input before incorporating it into a database query, allowing an attacker to manipulate the query and access sensitive information from the database.

  • No authentication required.
  • Input is concatenated into SQL.
  • Leads to unauthorized database access.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to execute arbitrary SQL commands. When a search is performed using the affected extension's search function, the input is not properly sanitized before being used in a database query. This could enable an attacker to read any data stored in the Joomla website's database.

  • Arbitrary database content could be read.
  • An attacker could inject SQL via a search parameter.
  • Sensitive site or user data may be exposed.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Joomla extension's unauthenticated SQL injection vulnerability in its search functionality is likely a concern for application owners and platform teams managing Joomla sites. The first practical step is to identify all instances of this extension, determine their internet reachability, and assess their business criticality to prioritize remediation efforts.

  • Identify vulnerable extension deployments.
  • Verify public exposure and business impact.
  • Plan coordinated vendor engagement for updates.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the OrdaSoft Joomla Gallery extension?

It is a third-party add-on for the Joomla content management system designed to display image galleries on websites. It includes features like a searchable interface that allows site visitors to find specific media, which is the component affected by this vulnerability.

How does CVE-2026-88854 allow SQL injection?

This is a CWE-89 weakness where the extension fails to properly clean input provided to its search box. Because the code treats search text as a direct part of the database command instead of treating it as data, an attacker can manipulate the query to trick the database into revealing unintended information.

Do I need to be logged in to trigger this bug?

No. The vulnerability exists within public-facing search functions designed for any anonymous site visitor to use. Sending a malicious search request does not require an account, as the underlying code processes the input before any authentication check would occur.

Is my site at risk according to Halo Surface Signal?

Yes, if you use this extension, Halo Surface Signal flags it as external and very likely reachable. Because the search module is intended to be public-facing, the attack surface is exposed to the internet by default as part of normal website operations.

What should I do if I run this technology?

First, inventory your Joomla environment to confirm if the OrdaSoft Gallery extension is installed and active. Check the official OrdaSoft website for version information and prioritize updating to a release at or above 6.2.7 to secure your database against unauthorized access.

References