๐Ÿ” CVE Alert

CVE-2026-102776

UNKNOWN 0.0

Joomla Extension - svenbluege.de - Cross-site request forgery of list tasks of the backend in Event Gallery extension < 6.6.0

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Joomla Extension - svenbluege.de - Cross-site request forgery of list tasks of the backend in Event Gallery extension < 6.6.0 - Eight tasks which the buttons of the back-end lists call did not check the form token: setting the default payment method, shipping method, image type set, order status and watermark; putting an event into the shop or taking it out; choosing the main image of an event and whether an image is shown only as the main image; and sorting the images of an event. A prepared page on another web site could trigger them in the name of a logged in administrator and change those settings and flags. Nothing can be deleted or read this way; orders are not affected.

CWE CWE-352
Vendor svenbluege.de
Product event gallery for joomla
Published Oct 5, 2026
Last Updated Oct 5, 2026
Stay Ahead of the Next One

Get instant alerts for svenbluege.de event gallery for joomla

Be the first to know when new unknown vulnerabilities affecting svenbluege.de event gallery for joomla are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

svenbluege.de / Event Gallery for Joomla
1.0.0-6.6.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
svenbluege.de: https://www.svenbluege.de/