Le journal DFS
PHP
-
OrdaSoft Joomla Gallery : quatre CVE, dont SQLi non authentifiée et RCE privilégiées
P2 · Critique · CVE-2026-88854, CVE-2026-88855 — L’extension OrdaSoft Joomla Gallery avant 6.2.7 cumule une injection SQL non authentifiée, une injection SQL nécessitant le privilège core.manage…