CVE-2026-100747: CWE-352 Cross-Site Request Forgery (CSRF) in svenbluege.de Event Gallery for Joomla
Joomla Extension - svenbluege.de - CSRF in image upload in Event Gallery extension < 6.5.0 - Due to lack of an CSRF token check, a third-party site can upload files to an event and overwrite existing files with the same name.
AI Analysis
Technical Summary
The Event Gallery extension for Joomla (svenbluege.de) versions 1.0.0 through 6.0.0 suffers from a CSRF vulnerability in its image upload functionality. Because the extension does not verify a CSRF token, an attacker can trick an authenticated user into submitting a request that uploads files to an event, potentially overwriting existing files with the same filename.
Potential Impact
An attacker can exploit this vulnerability to upload arbitrary files to an event gallery and overwrite existing files without user interaction or consent. This could lead to unauthorized content modification or defacement. The CVSS 4.0 base score is 5.1 (medium severity), reflecting network attack vector, low complexity, and no user interaction required but requiring high privileges.
Mitigation Recommendations
No official patch or remediation information is provided. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, users should consider restricting access to the image upload functionality or implementing additional CSRF protections at the application or web server level.
CVE-2026-100747: CWE-352 Cross-Site Request Forgery (CSRF) in svenbluege.de Event Gallery for Joomla
Description
Joomla Extension - svenbluege.de - CSRF in image upload in Event Gallery extension < 6.5.0 - Due to lack of an CSRF token check, a third-party site can upload files to an event and overwrite existing files with the same name.
CVSS v4.0
Score 5.1medium
Affected software
svenbluege.de
Event Gallery for Joomla
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Event Gallery extension for Joomla (svenbluege.de) versions 1.0.0 through 6.0.0 suffers from a CSRF vulnerability in its image upload functionality. Because the extension does not verify a CSRF token, an attacker can trick an authenticated user into submitting a request that uploads files to an event, potentially overwriting existing files with the same filename.
Potential Impact
An attacker can exploit this vulnerability to upload arbitrary files to an event gallery and overwrite existing files without user interaction or consent. This could lead to unauthorized content modification or defacement. The CVSS 4.0 base score is 5.1 (medium severity), reflecting network attack vector, low complexity, and no user interaction required but requiring high privileges.
Mitigation Recommendations
No official patch or remediation information is provided. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, users should consider restricting access to the image upload functionality or implementing additional CSRF protections at the application or web server level.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Joomla
- Date Reserved
- 2026-09-26T13:42:33.885Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ab9060ff7a7c54106fadfa5
Added to database: 09/27/2026, 12:03:27 UTC
Last enriched: 09/27/2026, 12:17:48 UTC
Last updated: 09/28/2026, 01:57:31 UTC
Views: 15
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.