CVE-2026-88857
— UNSCOREDPublished 2026-09-20 · Updated 2026-09-21
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions saveWatermark() copied an uploaded file into a web-accessible directory using the client-supplied filename exactly as sent, with no extension check, no content check, and no filename sanitisation of any kind. An authenticated core.manage user could upload a .php file disguised with an image Content-Type header and execute it directly by requesting the resulting path.
Weaknesses
CWE-434
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- CRITICALCVE-2026-14175
- HIGHCVE-2026-14553
- MEDIUMCVE-2026-16548
- CRITICALCVE-2026-16618
- HIGHCVE-2026-18788PoC
- HIGHCVE-2026-18933
- HIGHCVE-2026-36467PoC
- UNSCOREDCVE-2026-52835PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.