Security
OS Gallery 6.2.7 fixes four Joomla vulnerabilities
OrdaSoft's OS Gallery for Joomla contains four vulnerabilities in versions through 6.2.6, including a critical SQL injection that requires no login. Version 6.2.7 fixes the issues.
mySites.guru published research covering four flaws in OrdaSoft's OS Gallery. The disclosure does not report known active exploitation.
CVE-2026-88854is an unauthenticated SQL injection in the search module, rated Critical with a CVSS 4.0 score of 9.3.CVE-2026-88856andCVE-2026-88857are authenticated remote-code-execution vulnerabilities, both rated Critical at 9.4. They require an account with thecore.managepermission for OS Gallery.CVE-2026-88855is a second authenticated SQL injection, rated High at 8.6 and requiring the same permission.
All versions up to and including 6.2.6 are affected, while 6.2.7 is identified as the fixed release. Administrators should update OS Gallery, including the Light edition, as soon as possible. Sites where a gallery-manager account may have been compromised should also be checked for unauthorized files or other signs of code execution.
Originally reported by mySites.guru.