Event Gallery Core 6.6.0 Stable Security: Medium
6.6.0 makes orders, payments and mails more reliable and prepares Event Gallery for Joomla 7. It fixes three vulnerabilities, see Security Fixes.
Security Fixes
-
Forged changes from the lists of the backend (EGSA-2026-06, CVE-2026-102776, severity 5.1). Eight buttons of the backend lists did not check Joomla’s form token: the default of the payment and shipping methods, of the image type sets, order statuses and watermarks; In shop of an event; the main image of an event and whether an image is shown only as the main image; and the sorting of an event’s images. A prepared page on another website could have triggered them while you were logged in to the backend and changed those settings and flags. Nothing could be deleted or read this way, and orders were not affected. All eight need the token now, and the star and the table icon of the image list submit the list like the publish icon next to them instead of following a link. If you have a template override of
tmpl/files/default.phpof the backend, take over these two buttons from the new file; the old links stop with the token warning. -
The Google Photos picker could be made to send its access token elsewhere (EGSA-2026-07, CVE-2026-102777, severity 5.1). The upload page fetches the thumbnails of the Google Photos picker through your server, with the access token of the Google Photos account. The address to fetch came from the request and was not checked, and the request needed no form token: a prepared page on another website could make your server send the token of your Google Photos account to any address, or fetch addresses inside your network, while you were logged in to the backend; a backend user with the permission to manage Event Gallery could do the same directly. Only sites with a Google Photos account are affected, from 5.4.0 on. The server now fetches only addresses of Google’s image hosts, and the picker requests need the form token. Nothing changes for you when you use the picker.
-
The page a shared image link opens could run a script or lead to another website (EGSA-2026-08, severity 2.3, Low). With the option Share article links on, this page links the article the image was shared from. It took the address of the article from the shared link and printed it as it came, and with the link type Image Page with Redirect it followed the address at once. A prepared link could therefore run a script in the page, in the session of the visitor who opened it, or send the visitor to another website. Only sites with Share article links on are affected, from 3.11.6 on; the option is off unless you switched it on. The page now follows only an address of your own site and escapes it; shared links keep working. Until you update, switch Share article links off in the options of Event Gallery, tab Social.
-
Authorising a Google Photos account on Google now carries a random state which the callback checks against your session, so a callback which did not start from your account form is not followed.
Migration Hints
-
If you have a template override of the last page of the checkout (
checkout/review.phpofcom_eventgallery), add this field next totoken(); ?>:input type="hidden" name="reviewed_total" value="esc(number_format((float)$cart->getTotal()->getAmount(), 2, '.', '')) ?>"/>. It tells the shop which total the customer saw. -
The Stripe method no longer offers SEPA Direct Debit, Sofort and Giropay. A SEPA debit is paid days later, which Event Gallery could not follow, and Stripe has retired the other two. Your customers pay with the other methods you switched on, or by card.
-
Event Gallery comes with English and German texts only. If your site shows Event Gallery in another language with language files of your own or of a translation team, translate the texts which are new or changed in this version as well, for example with Joomla’s language overrides; until then Joomla shows these texts in English.
-
If you switched the mail off in the Global Configuration (Send Mail: No), your shop now takes orders and payments anyway; the mails it could not send are listed in
administrator/logs/com_eventgallery_order.log.php.
Ready for Joomla 7
-
Event Gallery no longer uses what Joomla 7 removes and keeps running on Joomla 5.0 and later (#1763). The Smart Search plugins work again on Joomla 5.0 to 5.3, and the JSitemap integration no longer needs Joomla’s backward compatibility plugin.
Improvements
-
Searching the order list while a status filter is set finds the matching orders again; before, it found none.
-
The search of the order list also finds the name and the company of the buyer.
-
The order list is more compact and works on a phone: one row shows the customer, the three statuses with a colored dot, the images and the total, and the columns can be sorted like every Joomla list. The pencil next to the statuses opens a row below an order to change them without opening it.
-
The order page starts with an overview and shows the images as a table with the price the buyer paid, the status next to them with a note that Paid and Shipped send an email, and the customer and the addresses. The list for the photo lab and the payment data are collapsed under Technical details, and the list can be copied with one click.
-
The list of order statuses shows the order, payment and shipping statuses in a group each, with the color of every status, and the arrows move a status within its group.
Bug Fixes
-
An order mail which cannot be sent no longer stops the checkout or the payment. The order goes on, and you are told which mail failed and why. Sharing or reporting an image shows a message instead of an error page, too.
-
An order is only placed at the total the customer saw on the last page of the checkout. If a promotion ended or a price changed meanwhile, the page shows the new total and the customer decides.
-
A free order is always set to paid and always gets a confirmation with its downloads.
-
Stripe charges currencies without decimals (yen, won, …) and with three decimals correctly; it charged a hundred times or a tenth of the price.
-
A PayPal payment notification which your server could not verify with PayPal is sent again by PayPal later, so the paid order no longer stays unpaid.
-
Deleting a payment or shipping method no longer breaks the orders and carts which used it.
-
A failed save in the backend no longer carries its input into the next order or file you open in the list.
-
The link of the hint The Download ID is missing could open an update site which Joomla cannot edit, and Joomla stopped with the error
getDownloadKey(): Argument #1 ($extension) must be of type stdClass, null given. The hint now links only the update site of the installed package, or tells you how to rebuild the update sites when there is none. An update from Event Gallery Core to Extended no longer leaves the update site of the Core package behind.
Event Gallery Core - Install Package
| File size | 3.72 Mb |
| SHA-512 Signature | e70fdc72a07064886c8a3b7fe4b6390c4bee4b303ebd7434e1336551d50a5a893aabcf05076199596cd95f2025a8a1cda4f860bd31c59dff8acc8a0bde6d12b8 |
| Compatibility |
Use this file to install Event Gallery Core through the Joomla Extension Manager. It can be used for updates and new installations.
If you perform an update there is no need to uninstall the package first. Just install it as you would do it with a new package. Keep in mind that uninstalling the package first would remove all you current data.
EventGallery.pdf
| File size | 39.58 Mb |
| SHA-512 Signature | d5db6482506c4eb912d8cde081d7a62c3fbd97aec7c743107e01471415b923336e32375849e2150109d95a615620e2e395f39b73a238b295ecefe7235254fe9d |