CVE-2026-97164: Joomla Extension - svenbluege.de - Path Traversal in Clear Cache task in Event Gallery extension < 6.5.0
Published Sep 27, 2026
·Updated
Joomla Extension - svenbluege.de - Authenticated arbitrary path deletion in clear cache task in Event Gallery extension < 6.5.0 - Using the images parameter of the cache.process task, you can recursively delete any directories that the web server is authorized to write to.
Affected Software
1 affected component
svenbluege.de Event Gallery<6.5.0
Event History
Sep 27, 2026
CVE Published
via MITRE·11:51 AM
Data Sourced
via MITRE·11:51 AM
DescriptionWeakness
Data Sourced
via NVD·12:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An authenticated user able to invoke the Event Gallery `cache.process` task can exploit it. The impact is limited to directories that the web server account is authorized to write to.
2
What attacker-controlled input is involved?
The issue is triggered through the `images` parameter of the `cache.process` task. A crafted value can cause recursive deletion of arbitrary writable directories.
3
Which versions are affected?
Event Gallery versions earlier than 6.5.0 are affected.