OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-94130

CRITICAL · CVSS 9.3 EPSS 0.38%

Source: NVD + CISA KEV + EPSS · Published 2026-09-26 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

The YouTube Gallery extension for Joomla versions prior to 5.7.3 is vulnerable to an unauthenticated SQL injection, enabling attackers to execute arbitrary SQL commands through the video search and sorting features. This critical vulnerability could lead to unauthorized data access or manipulation, posing significant risks to the integrity of the affected systems. Joomla administrators and users of the extension should prioritize applying the latest updates to mitigate potential exploitation.

CVE
CVE-2026-94130
Severity
CRITICAL
CVSS
9.3
EPSS
0.38%

Original NVD Description

Joomla Extension - joomlaboat.com - Unauthenticated SQL injection in YouTube Gallery extension < 5.7.3 - An SQL injection vulnerability in video search functionality and sorting allowed attackers to inject SQL commands in read queries.