Security
Critical SQL injection fixed in JoomlaBoat YouTube Gallery
JoomlaBoat’s YouTube Gallery extension for Joomla contains a critical unauthenticated SQL injection, affecting versions through 5.7.2 and fixed in 5.7.3.
mySites.guru reported that CVE-2026-94130 affects every release from 1.0.0 to 5.7.2. The flaw is reachable through the extension’s public video search and friendly-URL routing, so an attacker does not need an account or user interaction. The Joomla CNA assigned it a CVSS 4.0 score of 9.3, rated Critical.
The SQL injection can affect the confidentiality, integrity and availability of data held by the Joomla database. mySites.guru said there is no known exploitation in the wild and that the issue was not listed in CISA’s Known Exploited Vulnerabilities catalogue when its report was published.
- Update
YouTube Galleryto5.7.3and verify the installed version afterwards. - Sites running the old 4.x line must move to
5.7.3; there is no separate 4.x security release. - If an update is not immediately possible, disable the component, its content plugin and its module until it can be applied.
Administrators should also review affected sites for unfamiliar administrator accounts or other signs of compromise.
Originally reported by mySites.guru.