Event Gallery 6.6.0 fixes three vulnerabilities. The maintainer, Sven Bluege, found two of them while the screens of the back end were reworked and one in a review of the front end; none was reported from outside.
| ID | Vulnerability | Severity | Affected versions | Fixed in | Needed to exploit |
|---|---|---|---|---|---|
Cross-site request forgery of list tasks of the back end | Medium (5.1) | all before 6.6.0, 4.3.3 included | 6.6.0 | no account; the victim is logged in to the back end with the permission to manage Event Gallery and opens a prepared page | |
Server-side request forgery in the Google Photos picker: the access token of the account sent to any address | Medium (5.1) | 5.4.0 to 6.5.0 | 6.6.0 | a Google Photos account in Event Gallery; then no account and a logged in administrator who opens a prepared page, or a back-end login with the permission to manage Event Gallery | |
Cross-site scripting and open redirect on the share mini page | Low (2.3) | 3.11.6 to 6.5.0, 4.3.3 included | 6.6.0 | the option Share article links on (off by default); no account; the victim is any visitor who opens a prepared link |
- Update Event Gallery to 6.6.0 or later. There is no fixed version for Event Gallery 4 or 5; 4.3.3 was a one-time exception for the advisories of September 2026 and does not fix these.
- Until you can update: ask everybody with the permission Manage of Event Gallery to log out of your site before they visit other web sites or open links from mails and messages. This limits EGSA-2026-06 and EGSA-2026-07.
- Until you can update: switch the option Share article links off (options of Event Gallery, tab Social). With the option off the page ignores the address, and sites which never switched it on are not affected by EGSA-2026-08.