Skip to main content
mySites.guru
J!Awards 2026mySites.guru is shortlisted for Your Favourite Tool in Your Joomla WorkflowVote by 11 OctoberHow to vote
CVE-2026-102776MediumPublished 4 October 2026

Event Gallery (com_eventgallery) below 6.6.0 - CSRF in Backend List Actions, Google Photos Token Leak (SSRF) and Reflected XSS

Event Gallery (Core and Extended) versions before 6.6.0 contain three security flaws, fixed by the vendor in 6.6.0 (4 October 2026). 1) CVE-2026-102776 (vendor advisory EGSA-2026-06, vendor severity 5.1 Medium): eight buttons in the backend lists did not check the Joomla form token (the default payment and shipping method, image type sets, order statuses and watermarks, In shop of an event, the main image of an event and the main-image-only flag, and the sorting of an event's images). A page on another website could trigger them while an administrator was logged in to the backend and change those settings and flags. Nothing could be deleted or read this way and orders were not affected. 2) CVE-2026-102777 (EGSA-2026-07, vendor severity 5.1 Medium): the Google Photos picker on the upload page fetched thumbnails through the server with the Google Photos access token, taking the address from the request without checking it and without a form token. A page on another website could make the server send the Google Photos access token to any address, or fetch addresses inside the server's network, while an administrator was logged in; a backend user allowed to manage Event Gallery could do the same directly. Only sites with a Google Photos account configured are affected, from 5.4.0 on. 3) EGSA-2026-08 (no CVE, vendor severity 2.3 Low): with the Share article links option switched on (off by default), the page a shared image link opens printed the article address from the link unescaped and, for the Image Page with Redirect link type, followed it, allowing a crafted link to run script in the visitor's session or redirect them to another site; from 3.11.6 on. Both CVE ids were reserved but not yet published by the Joomla CNA when this rule was added. Update to Event Gallery 6.6.0 or later (it requires Joomla 5.4 or Joomla 6 and PHP 8.2). If you override the backend layout tmpl/files/default.php in your template, take over the star and table-icon buttons from the new file. Until you can update, switch Share article links off (Event Gallery options, tab Social) and avoid browsing other sites while logged in to the backend.

Affected versions: < 6.6.0

Official record: cve.org · NVD

Every connected Joomla site is checked against this rule on each audit, and flagged if it runs an affected version.

Affected extensions and versions

Our disclosure post

Running an affected version on a site you manage?

A free audit tells you which of your Joomla and WordPress sites run an affected version, which are out of date, and which have not been backed up. No card required. If a site is already compromised, fix.mysites.guru is a single fixed fee per incident, usually resolved the same day.

Rules current as of 4 October 2026.