Stored XSS in JoomGallery by Joomla Extensions Vendor
CVE-2026-66917
8.6HIGH
What is CVE-2026-66917?
The JoomGallery extension for Joomla is susceptible to a stored cross-site scripting (XSS) vulnerability. This flaw allows authenticated users with the appropriate privileges to embed malicious JavaScript into uploaded images. When other users visit the affected page, the injected script executes in their browsers, potentially compromising their session and data security.
Affected Version(s)
JoomGallery extension for Joomla 4.0.0-4.3.0
