Cross-Site Request Forgery in Event Gallery Extension for Joomla by Svenbluege
CVE-2026-102776
5.1MEDIUM
What is CVE-2026-102776?
The Event Gallery extension for Joomla, developed by Svenbluege, is vulnerable to Cross-Site Request Forgery (CSRF) in versions prior to 6.6.0. This vulnerability allows an attacker to exploit the backend controls of the extension by crafting a malicious page that can send requests on behalf of an authenticated administrator. Specifically, the affected tasks include changing the default payment method, adjusting shipping options, modifying image settings, and managing event visibility. While sensitive data remains protected, administrators are at risk of having their configurations altered without their consent.
Affected Version(s)
Event Gallery for Joomla 1.0.0-6.6.0
