CSRF Vulnerability in Joomla Extension by Svenbluege
CVE-2026-100747
5.1MEDIUM
What is CVE-2026-100747?
A critical vulnerability exists in the Event Gallery extension for Joomla prior to version 6.5.0, where the absence of proper CSRF token validation allows an attacker on a third-party site to initiate unauthorized file uploads. This oversight enables malicious users to potentially overwrite existing files with the same name, leading to data loss or corruption. Website administrators are highly encouraged to update to the latest version to mitigate these risks and ensure the security of their sites.
Affected Version(s)
Event Gallery for Joomla 1.0.0-6.0.0
