Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.4
CVE-2026-88857: OrdaSoft Joomla Gallery extension lets logged‑in admins run code
CVE-2026-88857 · published 1 day ago
Summary
The free OrdaSoft Joomla Gallery extension for Joomla versions before 6.2.7 lets a user with administrator rights upload a file that the system saves without checking its type or name. An attacker could disguise a malicious script as an image, upload it, and then run it on the website, potentially taking control of the server. Install the latest version of the extension (6.2.7 or newer) and ensure file‑upload settings are tightened to prevent unauthorized scripts.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| ordasoft.com | ordasoft joomla gallery free extension for joomla | 1.0.0-6.2.6 |
| ordasoft.com | ordasoft joomla gallery extension for joomla | 1.0.0-6.2.6 |
Original advisory text
Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7
Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions saveWatermark() copied an uploaded file into a web-accessible directory using the client-supplied filename exactly as sent, with no extension check, no content check, and no filename sanitisation of any kind. An authenticated core.manage user could upload a .php file disguised with an image Content-Type header and execute it directly by requesting the resulting path.
References
Severity
9.4
Critical
CVSS 4.0: 9.4 (NVD)
Exploitation
EPSS <1%
Type
CWE-434Unrestricted File Upload
Timeline
Published20 Sep 2026
Updated21 Sep 2026
First seen20 Sep 2026
Track software like this
Free during beta