Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.4
CVE-2026-88856: OrdaSoft Joomla Gallery extension lets attackers run code
CVE-2026-88856 · published 1 day ago
Summary
The free OrdaSoft Joomla Gallery add‑on for Joomla versions before 6.2.7 lets a logged‑in user tell the system to execute any command it chooses. This can let an attacker take control of the server or steal data. Upgrade the extension to version 6.2.7 or newer, or remove it if you do not need it, and ensure only trusted users have access.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| ordasoft.com | ordasoft joomla gallery free extension for joomla | 1.0.0-6.2.6 |
| ordasoft.com | ordasoft joomla gallery extension for joomla | 1.0.0-6.2.6 |
Original advisory text
Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7
Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions updateOSGallery(), reached via task=update_osgallery, read a JSON request body and called the value of a method field as a live PHP function, passing the value of a package field as its single argument, with no allow-list or is_callable() check of any kind. Any function name compatible with a single argument was directly reachable, including system, exec, shell_exec, and passthru.
References
Severity
9.4
Critical
CVSS 4.0: 9.4 (NVD)
Exploitation
EPSS <1%
Type
CWE-94Code Injection
Timeline
Published20 Sep 2026
Updated21 Sep 2026
First seen20 Sep 2026
Track software like this
Free during beta