Security
Event Gallery 6.6.0 fixes three Joomla security flaws
Joomla extension Event Gallery 6.6.0 addresses three security issues, including two medium-severity vulnerabilities affecting older releases and a low-severity cross-site scripting flaw.
mySites.guru reported that the flaws affect Event Gallery Core and Extended installations below 6.6.0. The release was published by vendor Sven Bluege on 4 October 2026.
CVE-2026-102776is a medium-severity backend CSRF issue, rated 5.1, allowing a logged-in administrator’s session to be used to alter selected shop and gallery settings.CVE-2026-102777is a medium-severity token disclosure and server-side request forgery issue, also rated 5.1. It affects versions from5.4.0when Google Photos is configured, and could expose the service’s access token.EGSA-2026-08is a low-severity XSS and open-redirect issue affecting versions from3.11.6when shared article links are enabled. It has no CVE identifier.
The advisory reports no active exploitation. Administrators should update to 6.6.0. The release requires Joomla 5.4 or later, or Joomla 6, and PHP 8.2; sites on Joomla 3 or 4 must upgrade their CMS first. Until then, disable shared article links and review Event Gallery backend access.
Originally reported by mySites.guru.