CVE-2026-100747EPSS p3.3%
CVE-2026-100747CVE-2026-100747
Description
Joomla Extension - svenbluege.de - CSRF in image upload in Event Gallery extension < 6.5.0 - Due to lack of an CSRF token check, a third-party site can upload files to an event and overwrite existing files with the same name.
Scoring
| EPSS | 0.15% probability of exploitation · percentile 3.3% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-30 |