OS Gallery (com_osgallery) below 6.2.7 - Unauthenticated SQL Injection via Public Search Module
CVE-2026-88854 (CVSS 9.3): showSearchResult() and showSearchResultAjax() in OrdaSoft's OS Gallery component before 6.2.7 read the textsearch/searchText request parameter with $input->getVar(), which is not a real Joomla filter method and falls through to a filter that strips HTML tags but does not touch quotes or SQL syntax. The value is concatenated directly into a LIKE clause with no escaping. The endpoint requires no login: it is reached via the public, commonly-published mod_osgallery_search search box, so any anonymous site visitor can inject a UNION SELECT and read arbitrary database content, including password hashes. Update to 6.2.7 or later.
Affected versions: < 6.2.7
Full advisory: www.cve.org
