CVE-2026-102778
Received Received - Intake

XSS and Open Redirect in Event Gallery Joomla Extension

Vulnerability report for CVE-2026-102778, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: Joomla! Project

Description

Joomla Extension - svenbluege.de - Cross-site scripting and open redirect on the share mini page in Event Gallery extension < 6.6.0 - The page a shared image link opens (the share mini page of the front end) can link the article the image was shared from when the option "Share article links" is on. It took the address of the article from the shared link and printed it into the page without checking or escaping it; with the link type "Image Page with Redirect" it followed the address at once. A prepared link could therefore run a script in the page, in the session of the visitor who opened it, or send the visitor to another web site. Nothing on the server is changed or read by the server.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
svenbluege.de Event Gallery for Joomla 1.0.0-6.6.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-601 The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
CWE-352 The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a cross-site scripting (XSS) and open redirect issue in the Event Gallery Joomla extension versions below 6.6.0. It occurs on the share mini page when the 'Share article links' option is enabled. The page fails to properly sanitize or escape the article link from the shared image URL, allowing malicious scripts to execute in a visitor's browser session or redirect them to another site.

Detection Guidance

This vulnerability can be detected by checking the version of the Event Gallery extension in your Joomla installation. If the version is below 6.6.0, the system is vulnerable. Inspect the extension's version via the Joomla admin panel or by examining the extension files in the server's file system.

Impact Analysis

If exploited, this vulnerability could allow attackers to run malicious scripts in your browser session when you open a shared image link, potentially stealing cookies, session tokens, or other sensitive data. It could also redirect you to phishing or malware sites without your knowledge.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by enabling cross-site scripting (XSS) and open redirect attacks. XSS may allow unauthorized execution of scripts in a user's session, risking data exposure or manipulation. Open redirects could trick users into visiting malicious sites, compromising confidentiality. However, the CVE does not provide specific details on compliance impacts.

Mitigation Strategies

Immediately update the Event Gallery extension to version 6.6.0 or higher. Disable the 'Share article links' option in the extension settings if not required. Review shared image links for suspicious URLs and monitor for unusual activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102778. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart