Affected versions: ≥ 4.0.0 and ≤ 4.4.1
Full advisory: www.cve.org
JoomGallery 4.0.0 to 4.4.1 ship a TUS resumable-upload endpoint with improper access control (CWE-284), letting an unauthenticated visitor upload files to the server. The Joomla CNA scored it CVSS 4.0 6.3 Medium. The attacker controls neither the file name nor the file extension, and code execution requires a non-standard server configuration, so a default install does not hand an attacker remote code execution. Found by Yugorin of Samar Group. No fixed version exists yet. The CVE record disagrees with itself on the affected range: its title says "JoomGallery < 4.4.1" while its structured version list says 4.0.0-4.4.1. The version list is the correct half. JoomGallery 4.4.1 (8 September 2026) is a bugfix release whose changelog lists ten non-security changes, and its TUS upload and access-control files are unchanged from 4.4.0, so the flaw is still present in the current release. The project has published no commits since that release. Until a fix ships, restrict access to the component TUS upload endpoint at the web server or WAF, and review the gallery upload directories for files you do not recognise. JoomGallery 3.x does not include the TUS server and is unaffected.
Affected versions: ≥ 4.0.0 and ≤ 4.4.1
Official record: cve.org · NVD
Every connected Joomla site is checked against this rule on each audit, and flagged if it runs an affected version.
Affected versions: ≥ 4.0.0 and ≤ 4.4.1
Full advisory: www.cve.org
A free audit tells you which of your Joomla and WordPress sites run an affected version, which are out of date, and which have not been backed up. No card required. If a site is already compromised, fix.mysites.guru is a single fixed fee per incident, usually resolved the same day.
Rules current as of 15 September 2026.