CVE-2026-102776
Received Received - Intake

Cross-Site Request Forgery in Event Gallery Joomla Extension

Vulnerability report for CVE-2026-102776, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: Joomla! Project

Description

Joomla Extension - svenbluege.de - Cross-site request forgery of list tasks of the backend in Event Gallery extension < 6.6.0 - Eight tasks which the buttons of the back-end lists call did not check the form token: setting the default payment method, shipping method, image type set, order status and watermark; putting an event into the shop or taking it out; choosing the main image of an event and whether an image is shown only as the main image; and sorting the images of an event. A prepared page on another web site could trigger them in the name of a logged in administrator and change those settings and flags. Nothing can be deleted or read this way; orders are not affected.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
svenbluege.de Event Gallery for Joomla 1.0.0-6.6.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-352 The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a Cross-Site Request Forgery (CSRF) flaw in the Event Gallery Joomla extension versions below 6.6.0. It allows attackers to trick administrators into executing unintended actions via malicious web pages. Eight backend list tasks lacked form token checks, enabling changes to settings like payment methods, shipping methods, image types, order status, watermarks, event shop status, main images, and image sorting without proper authorization.

Detection Guidance

This vulnerability affects the Event Gallery extension for Joomla versions prior to 6.6.0. To detect it, check the installed version of the Event Gallery component in your Joomla backend. If the version is below 6.6.0, the system is vulnerable. No specific commands are provided in the context, but you can verify the version through the Joomla administrator panel under Extensions > Manage > Manage.

Impact Analysis

An attacker could exploit this to modify backend settings, potentially altering payment gateways, watermarking, or image display rules. While data deletion or reading isn't possible, unauthorized changes could disrupt gallery functionality, affect sales, or misconfigure public-facing features. Requires a logged-in administrator to visit a malicious site.

Compliance Impact

This vulnerability allows unauthorized changes to settings like payment methods, watermarks, and image visibility via cross-site request forgery. This could lead to non-compliance with GDPR if personal data is exposed or modified without consent, or with HIPAA if protected health information is altered. The lack of form token checks enables unauthorized administrative actions that may violate data integrity and access control requirements.

Mitigation Strategies

Update the Event Gallery extension for Joomla to version 6.6.0 or higher to address the CSRF vulnerability in backend list tasks.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102776. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart