{"id":"CVE-2026-100747","published":"2026-09-27T12:17:10.557","lastModified":"2026-09-29T21:39:02.570","description":"Joomla Extension - svenbluege.de - CSRF in image upload in Event Gallery extension < 6.5.0 - Due to lack of an CSRF token check, a third-party site can upload files to an event and overwrite existing files with the same name.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":["CWE-352"],"vendors":[],"products":[],"references":[{"url":"https://www.svenbluege.de/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}