CVE-2026-102778

MEDIUM CVSS 4.0: 5.3 EPSS 0.15%
Updated Oct 06, 2026
Svenbluege.De
Parameter Value
CVSS 5.3 (MEDIUM)
Type CWE-601 (Open Redirect), CWE-352 (Cross-Site Request Forgery (CSRF))
Vendor Svenbluege.De
Public PoC No

Joomla Extension - svenbluege.de - Cross-site scripting and open redirect on the share mini page in Event Gallery extension < 6.6.0 - The page a shared image link opens (the share mini page of the front end) can link the article the image was shared from when the option "Share article links" is on. It took the address of the article from the shared link and printed it into the page without checking or escaping it; with the link type "Image Page with Redirect" it followed the address at once. A prepared link could therefore run a script in the page, in the session of the visitor who opened it, or send the visitor to another web site.

Nothing on the server is changed or read by the server.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Attack Requirements
None
No additional conditions
Privileges Required
None
No privileges needed
User Interaction
Passive
Minimal interaction

Impact Assessment

Confidentiality
Low
Partial data leak
Integrity
Low
Partial data modification
Availability
None
No disruption

CVSS Vector v4.0

Vulnerable Products

svenbluege.de:event gallery for joomla