CVE-2026-94130 CRITICAL

CVE-2026-94130: Joomla Extension - joomlaboat.com - Unauthenticated SQL injection in YouTube Gallery extension < 5.7.3

Vendor Joomlaboat.com
Product YouTube Gallery extension for Joomla
Weakness CWE-89 · SQLi
Published September 26, 2026
Last update September 26, 2026

CVSS base score

9.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality —
Integrity —

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Joomla Extension - joomlaboat.com - Unauthenticated SQL injection in YouTube Gallery extension < 5.7.3 - An SQL injection vulnerability in video search functionality and sorting allowed attackers to inject SQL commands in read queries.

Key dates

02Disclosure timeline

September 26, 2026 CVE published

Related vulnerabilities

04Related CVE