Skip to main content
mySites.guru
New features added last monthRelease RadarFile ManagerImpostor FilesUpdate QueueRogue AdminsMCP & APIJoomla VELCVE Index

JoomGallery security vulnerabilities

mySites.guru tracks 2 vulnerabilities in com_joomgallery. Every connected Joomla site is checked against them on each audit, and flagged if it runs an affected version.

What we check for

JoomGallery (com_joomgallery) 4.0.0 to 4.3.x - Authenticated Access to Password-Protected Content, Ownership Takeover and Stored XSS (CVE-2026-66916, CVE-2026-66917)

Every JoomGallery 4.x release from 4.0.0 up to and including the 4.3.x line carries two security flaws, present since the start of the 4.x branch. Both were reported to the vendor on 3 August 2026 by Toan Le and fixed in 4.4.0. CVE-2026-66916 (unauthorised access to protected content): information about images and categories can be read even when that content is meant to be protected. This mainly affects password-protected galleries, where details may be disclosed and, in some cases, the protected images themselves accessed or downloaded without authorisation. CVE-2026-66917 (ownership manipulation and JavaScript injection): a logged-in user holding edit permissions can reassign ownership of images or categories belonging to other users, which then grants them rights over content they never owned. The same flaw allows JavaScript to be injected through certain front-end views, so the injected code executes in the browser of anyone who later views that content (stored XSS). Exploitation requires a logged-in user with the relevant JoomGallery editing permissions, so the exposure is highest on galleries that let members edit content from the front end. The vendor rates both as medium risk and states that full system compromise is not possible. A gallery managed only by trusted administrators in the back end, with no front-end editing granted to other users, is at significantly lower practical risk. Fix: update to JoomGallery 4.4.0 or later, then review the editable content for anything already tampered with. If you use JoomGallery template overrides, apply the changes from the update to those overrides as well, otherwise an override can reintroduce the vulnerable output. Temporary mitigation until you can update: withdraw front-end JoomGallery edit permissions from all non-administrator user groups via the component ACL. This rule covers the Joomla 4/5/6 branch only. The separate JoomGallery 3.x branch for Joomla 3 is not covered by this advisory.

Affected versions: ≥ 4.0.0 and < 4.4.0

Full advisory: www.joomgalleryfriends.net

MediumCVE-2026-840482026-09-15

JoomGallery (com_joomgallery) 4.0.0 to 4.4.1 - Unauthenticated File Upload via the TUS Endpoint (no fixed version released)

JoomGallery 4.0.0 to 4.4.1 ship a TUS resumable-upload endpoint with improper access control (CWE-284), letting an unauthenticated visitor upload files to the server. The Joomla CNA scored it CVSS 4.0 6.3 Medium. The attacker controls neither the file name nor the file extension, and code execution requires a non-standard server configuration, so a default install does not hand an attacker remote code execution. Found by Yugorin of Samar Group. No fixed version exists yet. The CVE record disagrees with itself on the affected range: its title says "JoomGallery < 4.4.1" while its structured version list says 4.0.0-4.4.1. The version list is the correct half. JoomGallery 4.4.1 (8 September 2026) is a bugfix release whose changelog lists ten non-security changes, and its TUS upload and access-control files are unchanged from 4.4.0, so the flaw is still present in the current release. The project has published no commits since that release. Until a fix ships, restrict access to the component TUS upload endpoint at the web server or WAF, and review the gallery upload directories for files you do not recognise. JoomGallery 3.x does not include the TUS server and is unaffected.

Affected versions: ≥ 4.0.0 and ≤ 4.4.1

Full advisory: www.cve.org

Running JoomGallery on a site you manage?

A free audit tells you which of your Joomla and WordPress sites run an affected version, which are out of date, and which have not been backed up. No card required. If a site is already compromised, fix.mysites.guru is a single fixed fee per incident, usually resolved the same day.

CVE identifiers: CVE-2026-66917, CVE-2026-66916, CVE-2026-84048. Rules current as of 15 September 2026.