VulnSea

event_gallery_for_joomla vulnerabilities

CVEs whose affected-version data names the event_gallery_for_joomla package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

5 CVEsRSS

CVE-2026-97164High· 7.0
today

Joomla Extension - svenbluege.de - Authenticated arbitrary path deletion in `clear cache` task in Event Gallery extension < 6.5.0 - Using the `images` parameter of the `cache.process` task, you can recursively delete any directories that…

Joomla Extension - svenbluege.de - Authenticated arbitrary path deletion in `clear cache` task in Event Gallery extension < 6.5.0 - Using the `images` parameter of the `cache.process` task, you can recursively delete any directories that…

▾ Twilightsvenbluege.de · Event Gallery for Joomlavia NVD
CVE-2026-100748Medium· 6.9
today

Joomla Extension - svenbluege.de - CSRF in various cart actions in Event Gallery extension < 6.5.0

Joomla Extension - svenbluege.de - CSRF in various cart actions in Event Gallery extension < 6.5.0

▾ Sunlitsvenbluege.de · Event Gallery for Joomlavia NVD
CVE-2026-100747Medium· 5.1
today

Joomla Extension - svenbluege.de - CSRF in image upload in Event Gallery extension < 6.5.0 - Due to lack of an CSRF token check, a third-party site can upload files to an event and overwrite existing files with the same name.

Joomla Extension - svenbluege.de - CSRF in image upload in Event Gallery extension < 6.5.0 - Due to lack of an CSRF token check, a third-party site can upload files to an event and overwrite existing files with the same name.

▾ Sunlitsvenbluege.de · Event Gallery for Joomlavia NVD
CVE-2026-97165Medium· 5.3
today

Joomla Extension - svenbluege.de - Reflected XSS and open redirect in Event Gallery extension < 6.5.0 - The “return” parameter is base64-decoded and written to the “Back” link without being validated.

Joomla Extension - svenbluege.de - Reflected XSS and open redirect in Event Gallery extension < 6.5.0 - The “return” parameter is base64-decoded and written to the “Back” link without being validated.

▾ Sunlitsvenbluege.de · Event Gallery for Joomlavia NVD
CVE-2026-100749Medium· 5.1
today

Joomla Extension - svenbluege.de - CSRF in backend cleanup actions in Event Gallery extension < 6.5.0 - Only orphaned file entries and shopping carts that are older than 30 days will be deleted.

Joomla Extension - svenbluege.de - CSRF in backend cleanup actions in Event Gallery extension < 6.5.0 - Only orphaned file entries and shopping carts that are older than 30 days will be deleted.

▾ Sunlitsvenbluege.de · Event Gallery for Joomlavia NVD
event_gallery_for_joomla vulnerabilities (CVEs) · VulnSea