CVE-2026-100748: Joomla Extension - svenbluege.de - CSRF in various cart actions in Event Gallery extension < 6.5.0
Published Sep 27, 2026
·Updated
Joomla Extension - svenbluege.de - CSRF in various cart actions in Event Gallery extension < 6.5.0
Affected Software
1 affected component
svenbluege.de Event Gallery<6.5.0
Event History
Sep 27, 2026
CVE Published
via MITRE·11:51 AM
Data Sourced
via MITRE·11:51 AM
DescriptionWeakness
Data Sourced
via NVD·12:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which installations are affected?
The issue affects svenbluege.de Event Gallery versions earlier than 6.5.0.
2
What functionality is exposed?
The vulnerability involves cross-site request forgery in various cart actions within the Event Gallery extension.