Live This site runs Joomla 6.1.2
JoomClub

News, security and craft for the Joomla ecosystem

Security

Event Gallery 6.6.0 fixes three Joomla security flaws

Joomla extension Event Gallery 6.6.0 addresses three security issues, including two medium-severity vulnerabilities affecting older releases and a low-severity cross-site scripting flaw.

mySites.guru reported that the flaws affect Event Gallery Core and Extended installations below 6.6.0. The release was published by vendor Sven Bluege on 4 October 2026.

  • CVE-2026-102776 is a medium-severity backend CSRF issue, rated 5.1, allowing a logged-in administrator’s session to be used to alter selected shop and gallery settings.
  • CVE-2026-102777 is a medium-severity token disclosure and server-side request forgery issue, also rated 5.1. It affects versions from 5.4.0 when Google Photos is configured, and could expose the service’s access token.
  • EGSA-2026-08 is a low-severity XSS and open-redirect issue affecting versions from 3.11.6 when shared article links are enabled. It has no CVE identifier.

The advisory reports no active exploitation. Administrators should update to 6.6.0. The release requires Joomla 5.4 or later, or Joomla 6, and PHP 8.2; sites on Joomla 3 or 4 must upgrade their CMS first. Until then, disable shared article links and review Event Gallery backend access.

Originally reported by mySites.guru.