Affected versions: ≥ 4.0.0 and < 4.4.2
Full advisory: www.joomgalleryfriends.net
JoomGallery 4.0.0 to 4.4.1 ship a TUS resumable-upload endpoint with improper access control (CWE-284), letting an unauthenticated visitor upload files to the server. The Joomla CNA scored it CVSS 4.0 6.3 Medium. The vendor rates the practical risk as high and says it can be exploited on any JoomGallery 4.x installation, whatever the gallery configuration. The attacker controls neither the file name nor the file extension, so a default install does not hand over remote code execution, but on a poorly configured server the uploaded file may still be executable and the server compromised. Found by Yugorin of Samar Group, reported to the vendor on 12 September 2026. Uploaded files are dropped in the configured Joomla temp directory as a 32-character hexadecimal name alongside a matching .info file, for example aabbccddeeff00112233445566778899 and aabbccddeeff00112233445566778899.info. Fix: update to JoomGallery 4.4.2 (18 September 2026) or later. 4.4.2 adds a CSRF token check, a user identity check and per-category ACL checks to the TUS server, and enforces the configured upload size limit. After updating, inspect the Joomla temp directory, delete any files matching that pattern, and check the site for other signs of tampering. Temporary mitigation if you cannot update immediately: block access to the TUS upload endpoint of the component at the web server or WAF. The CVE record disagrees with itself on the affected range: the title says "JoomGallery < 4.4.1" while the structured version list says 4.0.0-4.4.1. The version list is the correct half, and the vendor confirms 4.4.1 is affected and 4.4.2 is the fix. JoomGallery 3.x does not include the TUS server and is unaffected.
The base metrics as Joomla CNA published them, and what each one means for a site running an affected version. Threat and environmental metrics are left out: they describe a moment or a particular install rather than the flaw.
6.3 Medium
CVSS 4.0, scored by Joomla CNACVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:AAffected versions: ≥ 4.0.0 and < 4.4.2
Full advisory: www.joomgalleryfriends.net
Updating for CVE-2026-84048 alone can leave a site on a release another rule still matches. These are the other flaws we check for in the same extension.
Latest safe version: 4.4.2
A free audit tells you which of your Joomla and WordPress sites run an affected version, which are out of date, and which have not been backed up. No card required. If a site is already compromised, fix.mysites.guru is a single fixed fee per incident, usually resolved the same day.
This check is part of the mySites.guru Joomla vulnerability scanner, which reads every installed extension's version on each audit. Browse the rest of the Joomla vulnerability database.
Rules current as of 8 October 2026.