EGSA-2026-06: Cross-site request forgery of list tasks of the back end

Eight tasks which the buttons of the back-end lists call did not check Joomla’s form token: setting the default payment method, shipping method, image type set, order status and watermark; putting an event into the shop or taking it out (In shop); choosing the main image of an event and whether an image is shown only as the main image; and sorting the images of an event. A prepared page on another web site could therefore trigger them in the name of a logged in administrator and change those settings and flags. Nothing can be deleted or read this way, and orders are not affected.

  • Needed: no account. The victim is logged in to the back end with the permission Manage of Event Gallery and opens a prepared page.
  • Affected: all versions before 6.6.0, 4.3.3 included.
  • Fixed in: 6.6.0. All eight tasks need the form token; the star and the table icon of the image list submit the list form instead of following a link.
  • Severity: CVSS 4.0 5.1 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N), CWE-352.
  • CVE: CVE-2026-102776.
All prices include VAT. The gross price will vary depending on the selected shipping country.