Live This site runs Joomla 6.1.2
JoomClub

News, security and craft for the Joomla ecosystem

Security

OS Gallery 6.2.7 fixes four Joomla vulnerabilities

OrdaSoft's OS Gallery for Joomla contains four vulnerabilities in versions through 6.2.6, including a critical SQL injection that requires no login. Version 6.2.7 fixes the issues.

mySites.guru published research covering four flaws in OrdaSoft's OS Gallery. The disclosure does not report known active exploitation.

  • CVE-2026-88854 is an unauthenticated SQL injection in the search module, rated Critical with a CVSS 4.0 score of 9.3.
  • CVE-2026-88856 and CVE-2026-88857 are authenticated remote-code-execution vulnerabilities, both rated Critical at 9.4. They require an account with the core.manage permission for OS Gallery.
  • CVE-2026-88855 is a second authenticated SQL injection, rated High at 8.6 and requiring the same permission.

All versions up to and including 6.2.6 are affected, while 6.2.7 is identified as the fixed release. Administrators should update OS Gallery, including the Light edition, as soon as possible. Sites where a gallery-manager account may have been compromised should also be checked for unauthorized files or other signs of code execution.

Originally reported by mySites.guru.