Live This site runs Joomla 6.1.2
JoomClub

News, security and craft for the Joomla ecosystem

Security

Critical SQL injection fixed in JoomlaBoat YouTube Gallery

JoomlaBoat’s YouTube Gallery extension for Joomla contains a critical unauthenticated SQL injection, affecting versions through 5.7.2 and fixed in 5.7.3.

mySites.guru reported that CVE-2026-94130 affects every release from 1.0.0 to 5.7.2. The flaw is reachable through the extension’s public video search and friendly-URL routing, so an attacker does not need an account or user interaction. The Joomla CNA assigned it a CVSS 4.0 score of 9.3, rated Critical.

The SQL injection can affect the confidentiality, integrity and availability of data held by the Joomla database. mySites.guru said there is no known exploitation in the wild and that the issue was not listed in CISA’s Known Exploited Vulnerabilities catalogue when its report was published.

  • Update YouTube Gallery to 5.7.3 and verify the installed version afterwards.
  • Sites running the old 4.x line must move to 5.7.3; there is no separate 4.x security release.
  • If an update is not immediately possible, disable the component, its content plugin and its module until it can be applied.

Administrators should also review affected sites for unfamiliar administrator accounts or other signs of compromise.

Originally reported by mySites.guru.