Server-Side Request Forgery Vulnerability in Event Gallery Extension by Svenbluege
CVE-2026-102777

6.3MEDIUM

Key Information:

Vendor
CVE Published:
5 October 2026

What is CVE-2026-102777?

The Event Gallery extension by Svenbluege is compromised by a server-side request forgery vulnerability stemming from the Google Photos picker feature. In versions earlier than 6.6.0, a lack of validation allows an adversary to exploit the backend upload page. The vulnerability permits the unauthorized fetching of content and the potential leakage of OAuth access tokens belonging to Google Photos accounts, effectively compromising user accounts if manipulated by a malicious actor. This exploitation can occur without proper verification of the request source, allowing an attacker to access sensitive data within the server's network, thereby posing significant risks to installed systems.

Affected Version(s)

Event Gallery for Joomla 1.0.0-6.6.0

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.