Cross-Site Request Forgery in Event Gallery Extension for Joomla by Svenbluege
CVE-2026-102776

5.1MEDIUM

Key Information:

Vendor
CVE Published:
5 October 2026

What is CVE-2026-102776?

The Event Gallery extension for Joomla, developed by Svenbluege, is vulnerable to Cross-Site Request Forgery (CSRF) in versions prior to 6.6.0. This vulnerability allows an attacker to exploit the backend controls of the extension by crafting a malicious page that can send requests on behalf of an authenticated administrator. Specifically, the affected tasks include changing the default payment method, adjusting shipping options, modifying image settings, and managing event visibility. While sensitive data remains protected, administrators are at risk of having their configurations altered without their consent.

Affected Version(s)

Event Gallery for Joomla 1.0.0-6.6.0

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.