Event Gallery Core 6.6.0 Stable Security: Medium

Released on: Sunday, 04 October 2026 12:02

6.6.0 makes orders, payments and mails more reliable and prepares Event Gallery for Joomla 7. It fixes three vulnerabilities, see Security Fixes.

Security Fixes

  • Forged changes from the lists of the backend (EGSA-2026-06, CVE-2026-102776, severity 5.1). Eight buttons of the backend lists did not check Joomla’s form token: the default of the payment and shipping methods, of the image type sets, order statuses and watermarks; In shop of an event; the main image of an event and whether an image is shown only as the main image; and the sorting of an event’s images. A prepared page on another website could have triggered them while you were logged in to the backend and changed those settings and flags. Nothing could be deleted or read this way, and orders were not affected. All eight need the token now, and the star and the table icon of the image list submit the list like the publish icon next to them instead of following a link. If you have a template override of tmpl/files/default.php of the backend, take over these two buttons from the new file; the old links stop with the token warning.

  • The Google Photos picker could be made to send its access token elsewhere (EGSA-2026-07, CVE-2026-102777, severity 5.1). The upload page fetches the thumbnails of the Google Photos picker through your server, with the access token of the Google Photos account. The address to fetch came from the request and was not checked, and the request needed no form token: a prepared page on another website could make your server send the token of your Google Photos account to any address, or fetch addresses inside your network, while you were logged in to the backend; a backend user with the permission to manage Event Gallery could do the same directly. Only sites with a Google Photos account are affected, from 5.4.0 on. The server now fetches only addresses of Google’s image hosts, and the picker requests need the form token. Nothing changes for you when you use the picker.

  • The page a shared image link opens could run a script or lead to another website (EGSA-2026-08, severity 2.3, Low). With the option Share article links on, this page links the article the image was shared from. It took the address of the article from the shared link and printed it as it came, and with the link type Image Page with Redirect it followed the address at once. A prepared link could therefore run a script in the page, in the session of the visitor who opened it, or send the visitor to another website. Only sites with Share article links on are affected, from 3.11.6 on; the option is off unless you switched it on. The page now follows only an address of your own site and escapes it; shared links keep working. Until you update, switch Share article links off in the options of Event Gallery, tab Social.

Hardening without a known vulnerability
  • Authorising a Google Photos account on Google now carries a random state which the callback checks against your session, so a callback which did not start from your account form is not followed.

Migration Hints

  • If you have a template override of the last page of the checkout (checkout/review.php of com_eventgallery), add this field next to token(); ?>: input type="hidden" name="reviewed_total" value="esc(number_format((float)$cart->getTotal()->getAmount(), 2, '.', '')) ?>"/>. It tells the shop which total the customer saw.

  • The Stripe method no longer offers SEPA Direct Debit, Sofort and Giropay. A SEPA debit is paid days later, which Event Gallery could not follow, and Stripe has retired the other two. Your customers pay with the other methods you switched on, or by card.

  • Event Gallery comes with English and German texts only. If your site shows Event Gallery in another language with language files of your own or of a translation team, translate the texts which are new or changed in this version as well, for example with Joomla’s language overrides; until then Joomla shows these texts in English.

  • If you switched the mail off in the Global Configuration (Send Mail: No), your shop now takes orders and payments anyway; the mails it could not send are listed in administrator/logs/com_eventgallery_order.log.php.

Ready for Joomla 7

  • Event Gallery no longer uses what Joomla 7 removes and keeps running on Joomla 5.0 and later (#1763). The Smart Search plugins work again on Joomla 5.0 to 5.3, and the JSitemap integration no longer needs Joomla’s backward compatibility plugin.

Improvements

Orders in the backend (#1874)
  • Searching the order list while a status filter is set finds the matching orders again; before, it found none.

  • The search of the order list also finds the name and the company of the buyer.

  • The order list is more compact and works on a phone: one row shows the customer, the three statuses with a colored dot, the images and the total, and the columns can be sorted like every Joomla list. The pencil next to the statuses opens a row below an order to change them without opening it.

  • The order page starts with an overview and shows the images as a table with the price the buyer paid, the status next to them with a note that Paid and Shipped send an email, and the customer and the addresses. The list for the photo lab and the payment data are collapsed under Technical details, and the list can be copied with one click.

Order statuses in the backend (#1881)
  • The list of order statuses shows the order, payment and shipping statuses in a group each, with the color of every status, and the arrows move a status within its group.

Bug Fixes

Orders, payments and mails (#1870)
  • An order mail which cannot be sent no longer stops the checkout or the payment. The order goes on, and you are told which mail failed and why. Sharing or reporting an image shows a message instead of an error page, too.

  • An order is only placed at the total the customer saw on the last page of the checkout. If a promotion ended or a price changed meanwhile, the page shows the new total and the customer decides.

  • A free order is always set to paid and always gets a confirmation with its downloads.

  • Stripe charges currencies without decimals (yen, won, …​) and with three decimals correctly; it charged a hundred times or a tenth of the price.

  • A PayPal payment notification which your server could not verify with PayPal is sent again by PayPal later, so the paid order no longer stays unpaid.

  • Deleting a payment or shipping method no longer breaks the orders and carts which used it.

  • A failed save in the backend no longer carries its input into the next order or file you open in the list.

Download ID
  • The link of the hint The Download ID is missing could open an update site which Joomla cannot edit, and Joomla stopped with the error getDownloadKey(): Argument #1 ($extension) must be of type stdClass, null given. The hint now links only the update site of the installed package, or tells you how to rebuild the update sites when there is none. An update from Event Gallery Core to Extended no longer leaves the update site of the Core package behind.

Event Gallery Core - Install Package

PHP 8.2 Joomla 5.4 Joomla 6.0 Joomla 6.1 Joomla 6.2

File size 3.72 Mb
SHA-512 Signature e70fdc72a07064886c8a3b7fe4b6390c4bee4b303ebd7434e1336551d50a5a893aabcf05076199596cd95f2025a8a1cda4f860bd31c59dff8acc8a0bde6d12b8
Compatibility PHP 8.2 Joomla 5.4 Joomla 6.0 Joomla 6.1 Joomla 6.2

Use this file to install Event Gallery Core through the Joomla Extension Manager. It can be used for updates and new installations.

If you perform an update there is no need to uninstall the package first. Just install it as you would do it with a new package. Keep in mind that uninstalling the package first would remove all you current data.

EventGallery.pdf

File size 39.58 Mb
SHA-512 Signature d5db6482506c4eb912d8cde081d7a62c3fbd97aec7c743107e01471415b923336e32375849e2150109d95a615620e2e395f39b73a238b295ecefe7235254fe9d
All prices include VAT. The gross price will vary depending on the selected shipping country.