Skip to main content
mySites.guru
J!Awards 2026mySites.guru is shortlisted for Your Favourite Tool in Your Joomla WorkflowVote by 11 OctoberHow to vote

OS Gallery security vulnerabilities

mySites.guru tracks 2 vulnerabilities in OS Gallery (com_osgallery), covering 4 CVEs. Every connected Joomla site is checked against them on each audit.

Is my site affected?

Your site is affected if it runs OS Gallery in this range:

  • before 6.2.7
Latest safe version
6.2.7 or later. No rule we check matches that release or any newer one.
What to do
Update OS Gallery to 6.2.7 or later from the vendor, then confirm the installed version on the Joomla administrator's Extensions: Manage screen.

Every OS Gallery vulnerability we track

Newest first. CVSS is the score published in each CVE record, where it has one; the severity column is the rating our check uses.

CVEAffected versionsFixed inSeverityAdded
CVE-2026-88854CVSS 9.3before 6.2.76.2.7Critical2026-09-20
CVE-2026-88857CVSS 9.4CVE-2026-88856CVSS 9.4CVE-2026-88855CVSS 8.6before 6.2.76.2.7Critical2026-09-20

What we check for

CriticalCVE-2026-888542026-09-20

OS Gallery (com_osgallery) below 6.2.7 - Unauthenticated SQL Injection via Public Search Module

CVE-2026-88854 (CVSS 9.3): showSearchResult() and showSearchResultAjax() in OrdaSoft's OS Gallery component before 6.2.7 read the textsearch/searchText request parameter with $input->getVar(), which is not a real Joomla filter method and falls through to a filter that strips HTML tags but does not touch quotes or SQL syntax. The value is concatenated directly into a LIKE clause with no escaping. The endpoint requires no login: it is reached via the public, commonly-published mod_osgallery_search search box, so any anonymous site visitor can inject a UNION SELECT and read arbitrary database content, including password hashes. Update to 6.2.7 or later.

Affected versions: < 6.2.7

Full advisory: www.cve.org

OS Gallery (com_osgallery) below 6.2.7 - Authenticated, Privileged Remote Code Execution and SQL Injection (3 CVEs)

OrdaSoft's OS Gallery component before 6.2.7 has three flaws exploitable by an authenticated user holding the core.manage permission on the gallery component (not administrator-wide trust). CVE-2026-88857 (CVSS 9.4): saveWatermark() writes an uploaded file to a web-accessible path using the client-supplied filename with no extension or content check, so a .php file disguised with an image Content-Type can be uploaded and executed directly. CVE-2026-88856 (CVSS 9.4): updateOSGallery(), reached via task=update_osgallery, passes a JSON request's method field to a live PHP function call using the package field as its argument, with no allow-list, reaching functions such as system, exec, shell_exec and passthru directly. CVE-2026-88855 (CVSS 8.6): saveGallery() concatenates category_names[], catOrderIds and image-ordering values into SQL with no quoting or integer cast, giving full read/write database access including UNION extraction of #__users password hashes. Update to 6.2.7 or later.

Affected versions: < 6.2.7

Full advisory: www.cve.org

Timeline

  1. 20 September 2026Check added for CVE-2026-88854 (before 6.2.7)
  2. 20 September 2026Check added for CVE-2026-88857, CVE-2026-88856 and CVE-2026-88855 (before 6.2.7)
  3. 20 September 2026CVE-2026-88854 record published
  4. 20 September 2026CVE-2026-88857 record published
  5. 20 September 2026CVE-2026-88856 record published
  6. 20 September 2026CVE-2026-88855 record published
  7. 20 September 2026We published: OS Gallery 6.2.7 Fixes an Unauthenticated SQL Injection and Two Authenticated RCEs

What we have written about OS Gallery

References

Each CVE page above links its official cve.org record and its NVD entry.

OS Gallery vulnerability questions

Which versions of OS Gallery are vulnerable?
mySites.guru tracks 2 vulnerabilities in OS Gallery (com_osgallery). A site is affected if its installed version is in this range: before 6.2.7.
What is the latest safe version of OS Gallery?
6.2.7. Every vulnerability tracked here is fixed by 6.2.7, and no rule we check matches that release or any later one.
How do I check which version of OS Gallery my Joomla site runs?
The installed version is listed on the Joomla administrator's Extensions: Manage screen; search it for com_osgallery. mySites.guru reads the installed version on every audit of a connected site and checks it against these rules.

Running OS Gallery on a site you manage?

A free audit tells you which of your Joomla and WordPress sites run an affected version, which are out of date, and which have not been backed up. No card required. If a site is already compromised, fix.mysites.guru is a single fixed fee per incident, usually resolved the same day.

This check is part of the mySites.guru Joomla vulnerability scanner, which reads every installed extension's version on each audit. Browse the rest of the Joomla vulnerability database.

CVE identifiers: CVE-2026-88854, CVE-2026-88857, CVE-2026-88856, CVE-2026-88855. Rules current as of 10 October 2026.