CVE-2026-100747: Joomla Extension - svenbluege.de - CSRF in image upload in Event Gallery extension < 6.5.0
Published Sep 27, 2026
·Updated
Joomla Extension - svenbluege.de - CSRF in image upload in Event Gallery extension < 6.5.0 - Due to lack of an CSRF token check, a third-party site can upload files to an event and overwrite existing files with the same name.
Affected Software
1 affected component
svenbluege.de Event Gallery<6.5.0
Event History
Sep 27, 2026
CVE Published
via MITRE·11:50 AM
Data Sourced
via MITRE·11:50 AM
DescriptionWeakness
Data Sourced
via NVD·12:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which installations are affected?
Event Gallery versions earlier than 6.5.0 are affected.
2
What does an attacker need to exploit this issue?
An attacker needs to cause a user’s browser to interact with the affected Event Gallery upload functionality from a third-party site. The vulnerability exists because the upload action does not verify a CSRF token.
3
What can exploitation allow?
A third-party site can upload files to an event and overwrite existing files when the uploaded file uses the same name.