The CVE-2026-97165 vulnerability is a reflected XSS and open redirect issue in the Event Gallery extension for Joomla, affecting versions less than 6.5.0. The 'return' parameter is base64-decoded and written to the 'Back' link without validation, leading to potential security risks. This issue can allow attackers to execute malicious scripts or redirect users to malicious sites. Defenders should assess ex [truncated]
Authenticated arbitrary path deletion in Joomla Event Gallery extension < 6.5.0 allows users to delete directories using the 'images' parameter of the 'cache.process' task, potentially leading to data loss or service disruption. Joomla site administrators and security teams should assess exposure and prioritize remediation. The vulnerability has a CVSS score of 7, indicating high severity. Affected users [truncated]
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Event Gallery extension for Joomla, version prior to 6.5.0. This vulnerability allows an attacker to perform unauthorized actions on behalf of a user in the backend cleanup actions, specifically for orphaned file entries and shopping carts older than 30 days. The vulnerability could lead to potential disruption of backend operations and unaut [truncated]
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Event Gallery extension for Joomla, version < 6.5.0. This vulnerability allows attackers to perform various cart actions without the user's consent. The Event Gallery extension handles cart actions in a way that does not properly validate requests, making it susceptible to CSRF attacks. To address this vulnerability, defenders should verify t [truncated]
The CVE-2026-100747 vulnerability is a CSRF issue in the Event Gallery extension for Joomla, allowing third-party sites to upload files and overwrite existing ones. Defenders should assess exposure, prioritize remediation, and verify affected versions. This issue affects versions prior to 6.5.0 and has a CVSS score of 5.1, indicating a medium severity. The vulnerability can lead to unauthorized file uploa [truncated]