September 2026: fixed in 6.5.0 and 4.3.3

Event Gallery 6.5.0 was released on 26 September 2026. It fixes five vulnerabilities. All of them were found by the maintainer, Sven Bluege, during regular maintenance; none was reported from outside.

Event Gallery 4.3.3 brings the fixes of four of them - all but EGSA-2026-04 - to Event Gallery 4, the version for Joomla 3 and Joomla 4. It changes nothing else.

IDVulnerabilitySeverityAffected versionsFixed inNeeded to exploit

EGSA-2026-01

Path traversal in Clear Cache: deleting any folder of the server

High (7.0)

all before 6.5.0 except 4.3.3

6.5.0, 4.3.3

a back-end login with the permission to manage Event Gallery

EGSA-2026-02

Cross-site scripting and open redirect on the front-end upload page

Medium (5.3)

3.11.4 to 6.0.0 except 4.3.3

6.5.0, 4.3.3

no account; the victim is logged in with the permission to edit Event Gallery and opens a prepared link

EGSA-2026-03

Cross-site request forgery of the upload

Medium (5.1)

all before 6.5.0 except 4.3.3

6.5.0, 4.3.3

no account; the victim is logged in with the permission to edit Event Gallery and opens a prepared page

EGSA-2026-04

Cross-site request forgery of the cart

Medium (6.9)

all before 6.5.0, 4.3.3 included

6.5.0

no account; the victim is any visitor who opens a prepared page

EGSA-2026-05

Cross-site request forgery of the clean-up links of the back end

Medium (5.1)

all before 6.5.0 except 4.3.3

6.5.0, 4.3.3

no account; the victim is logged in to the back end with the permission to manage Event Gallery and opens a prepared page

The permissions are the ones of Event Gallery, which you set in its options on the tab Permissions. In Joomla’s default permissions, Manage (core.manage) belongs to the groups Administrator and Super Users, and Edit (core.edit) to Editor, Publisher, Manager, Administrator and Super Users.

What to do

  • Joomla 5.4 or Joomla 6: update Event Gallery to 6.5.0 or later.
  • Joomla 5.0 to 5.3: Event Gallery 6.5.0 needs Joomla 5.4. Update Joomla first, then Event Gallery.
  • Joomla 3, or Joomla 4 with Event Gallery 4: update Event Gallery to 4.3.3. It fixes all of them except EGSA-2026-04, whose fix needs new scripts in the cart; the buyer sees the cart again before an order is placed. 4.3.3 is a one-time exception, there will be no further fixes for Joomla 3 and Joomla 4: plan the update to Joomla 5.4 or later and Event Gallery 6.5.0.
  • Joomla 4 with Event Gallery 5: Event Gallery 5.7.8 is the last version for Joomla 4, and there is no fixed version for it. Update Joomla to 5.4 or later and Event Gallery to 6.5.0, or protect your site as described below.

Until you can update:

  • Give the permission Manage of Event Gallery only to people you would also trust with the files of your server. This limits EGSA-2026-01.
  • Ask everybody with the permission Edit or Manage of Event Gallery to log out of your site before they visit other web sites or open links from mails and messages. This limits EGSA-2026-02, EGSA-2026-03 and EGSA-2026-05.
All prices include VAT. The gross price will vary depending on the selected shipping country.