Authenticated Path Deletion Vulnerability in Event Gallery Extension by Svenbluege
CVE-2026-97164

7HIGH

Key Information:

Vendor
CVE Published:
27 September 2026

What is CVE-2026-97164?

The Event Gallery extension by Svenbluege contains a security flaw that permits authenticated users to delete arbitrary paths through the clear cache task. By leveraging the images parameter in the cache.process task, users can recursively remove directories that the web server has permissions to write to. This exposes systems to risks where critical files or directories can be compromised.

Affected Version(s)

Event Gallery for Joomla 1.0.0-6.0.0

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.