CVE-2026-66917
Received Received - Intake

Stored XSS in JoomGallery Extension Prior to 4.4.0

Vulnerability report for CVE-2026-66917, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-22

Last updated on: 2026-08-22

Assigner: Joomla! Project

Description

Joomla Extension - joomgalleryfriends.net - Stored XSS in JoomGallery < 4.4.0 - An authenticated, privileged can store an XSS payload in any image causing JS execution in every visitor's browser.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-22
Last Modified
2026-08-22
Generated
2026-08-22
AI Q&A
2026-08-22
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
joomgalleryfriends joomgallery to 4.4.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a stored cross-site scripting (XSS) vulnerability in the JoomGallery extension for Joomla, affecting versions before 4.4.0. An authenticated, privileged user can inject malicious JavaScript code into image metadata. When other users view the image, the script executes in their browsers, potentially stealing data or performing unauthorized actions.

Impact Analysis

If you use JoomGallery versions below 4.4.0, attackers with admin access could compromise your website by stealing user sessions, defacing pages, or spreading malware. Visitors to your site may also have their data exposed or devices infected through the injected scripts.

Compliance Impact

This vulnerability could lead to unauthorized data access or exfiltration, violating GDPR's data protection principles or HIPAA's security requirements. Organizations may face fines or legal consequences if user data is compromised due to this flaw.

Mitigation Strategies

Upgrade JoomGallery to version 4.4.0 or later to patch the stored XSS vulnerability. Ensure only authenticated privileged users can access the system and review image metadata for suspicious payloads.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-66917. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart