Skip to main content
mySites.guru
J!Awards 2026mySites.guru is shortlisted for Your Favourite Tool in Your Joomla WorkflowVote by 11 OctoberHow to vote

JoomGallery security vulnerabilities

mySites.guru tracks 2 vulnerabilities in JoomGallery (com_joomgallery), covering 3 CVEs. Every connected Joomla site is checked against them on each audit.

Is my site affected?

Your site is affected if it runs JoomGallery in any of these ranges:

  • from 4.0.0 up to but not including 4.4.2
  • from 4.0.0 up to but not including 4.4.0
Latest safe version
4.4.2 or later. No rule we check matches that release or any newer one.
What to do
Update JoomGallery to 4.4.2 or later from the vendor, then confirm the installed version on the Joomla administrator's Extensions: Manage screen.

Every JoomGallery vulnerability we track

Newest first. CVSS is the score published in each CVE record, where it has one; the severity column is the rating our check uses.

CVEAffected versionsFixed inSeverityAdded
CVE-2026-84048CVSS 6.3from 4.0.0 up to but not including 4.4.24.4.2Medium2026-09-15
CVE-2026-66917CVSS 8.6CVE-2026-66916CVSS 6.9from 4.0.0 up to but not including 4.4.04.4.0High2026-08-22

What we check for

JoomGallery (com_joomgallery) 4.0.0 to 4.3.x - Authenticated Access to Password-Protected Content, Ownership Takeover and Stored XSS (CVE-2026-66916, CVE-2026-66917)

Every JoomGallery 4.x release from 4.0.0 up to and including the 4.3.x line carries two security flaws, present since the start of the 4.x branch. Both were reported to the vendor on 3 August 2026 by Toan Le and fixed in 4.4.0. CVE-2026-66916 (unauthorised access to protected content): information about images and categories can be read even when that content is meant to be protected. This mainly affects password-protected galleries, where details may be disclosed and, in some cases, the protected images themselves accessed or downloaded without authorisation. CVE-2026-66917 (ownership manipulation and JavaScript injection): a logged-in user holding edit permissions can reassign ownership of images or categories belonging to other users, which then grants them rights over content they never owned. The same flaw allows JavaScript to be injected through certain front-end views, so the injected code executes in the browser of anyone who later views that content (stored XSS). Exploitation requires a logged-in user with the relevant JoomGallery editing permissions, so the exposure is highest on galleries that let members edit content from the front end. The vendor rates both as medium risk and states that full system compromise is not possible. A gallery managed only by trusted administrators in the back end, with no front-end editing granted to other users, is at significantly lower practical risk. Fix: update to JoomGallery 4.4.0 or later, then review the editable content for anything already tampered with. If you use JoomGallery template overrides, apply the changes from the update to those overrides as well, otherwise an override can reintroduce the vulnerable output. Temporary mitigation until you can update: withdraw front-end JoomGallery edit permissions from all non-administrator user groups via the component ACL. This rule covers the Joomla 4/5/6 branch only. The separate JoomGallery 3.x branch for Joomla 3 is not covered by this advisory.

Affected versions: ≥ 4.0.0 and < 4.4.0

Full advisory: www.joomgalleryfriends.net

MediumCVE-2026-840482026-09-15

JoomGallery (com_joomgallery) 4.0.0 to 4.4.1 - Unauthenticated Arbitrary File Upload via the TUS Endpoint (CVE-2026-84048)

JoomGallery 4.0.0 to 4.4.1 ship a TUS resumable-upload endpoint with improper access control (CWE-284), letting an unauthenticated visitor upload files to the server. The Joomla CNA scored it CVSS 4.0 6.3 Medium. The vendor rates the practical risk as high and says it can be exploited on any JoomGallery 4.x installation, whatever the gallery configuration. The attacker controls neither the file name nor the file extension, so a default install does not hand over remote code execution, but on a poorly configured server the uploaded file may still be executable and the server compromised. Found by Yugorin of Samar Group, reported to the vendor on 12 September 2026. Uploaded files are dropped in the configured Joomla temp directory as a 32-character hexadecimal name alongside a matching .info file, for example aabbccddeeff00112233445566778899 and aabbccddeeff00112233445566778899.info. Fix: update to JoomGallery 4.4.2 (18 September 2026) or later. 4.4.2 adds a CSRF token check, a user identity check and per-category ACL checks to the TUS server, and enforces the configured upload size limit. After updating, inspect the Joomla temp directory, delete any files matching that pattern, and check the site for other signs of tampering. Temporary mitigation if you cannot update immediately: block access to the TUS upload endpoint of the component at the web server or WAF. The CVE record disagrees with itself on the affected range: the title says "JoomGallery < 4.4.1" while the structured version list says 4.0.0-4.4.1. The version list is the correct half, and the vendor confirms 4.4.1 is affected and 4.4.2 is the fix. JoomGallery 3.x does not include the TUS server and is unaffected.

Affected versions: ≥ 4.0.0 and < 4.4.2

Full advisory: www.joomgalleryfriends.net

Timeline

  1. 22 August 2026Check added for CVE-2026-66917 and CVE-2026-66916 (from 4.0.0 up to but not including 4.4.0)
  2. 22 August 2026CVE-2026-66917 record published
  3. 22 August 2026CVE-2026-66916 record published
  4. 15 September 2026Check added for CVE-2026-84048 (from 4.0.0 up to but not including 4.4.2)
  5. 15 September 2026CVE-2026-84048 record published
  6. 19 September 2026We published: JoomGallery 4.4.2 Fixes an Unauthenticated File Upload

What we have written about JoomGallery

References

Each CVE page above links its official cve.org record and its NVD entry.

JoomGallery vulnerability questions

Which versions of JoomGallery are vulnerable?
mySites.guru tracks 2 vulnerabilities in JoomGallery (com_joomgallery). A site is affected if its installed version is in any of these ranges: from 4.0.0 up to but not including 4.4.2; from 4.0.0 up to but not including 4.4.0.
What is the latest safe version of JoomGallery?
4.4.2. Every vulnerability tracked here is fixed by 4.4.2, and no rule we check matches that release or any later one.
How do I check which version of JoomGallery my Joomla site runs?
The installed version is listed on the Joomla administrator's Extensions: Manage screen; search it for com_joomgallery. mySites.guru reads the installed version on every audit of a connected site and checks it against these rules.

Running JoomGallery on a site you manage?

A free audit tells you which of your Joomla and WordPress sites run an affected version, which are out of date, and which have not been backed up. No card required. If a site is already compromised, fix.mysites.guru is a single fixed fee per incident, usually resolved the same day.

This check is part of the mySites.guru Joomla vulnerability scanner, which reads every installed extension's version on each audit. Browse the rest of the Joomla vulnerability database.

CVE identifiers: CVE-2026-66917, CVE-2026-66916, CVE-2026-84048. Rules current as of 8 October 2026.