Medium severityNVD Advisory· Published Sep 27, 2026
CVE-2026-100747
CVE-2026-100747
Description
Joomla Extension - svenbluege.de - CSRF in image upload in Event Gallery extension < 6.5.0 - Due to lack of an CSRF token check, a third-party site can upload files to an event and overwrite existing files with the same name.
Affected products
1- Range: <6.5.0
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.