{"id":"CVE-2026-97164","published":"2026-09-27T12:17:11.987","lastModified":"2026-09-29T21:39:02.570","description":"Joomla Extension - svenbluege.de - Authenticated arbitrary path deletion in `clear cache` task in Event Gallery extension < 6.5.0 - Using the `images` parameter of the `cache.process` task, you can recursively delete any directories that the web server is authorized to write to.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":["CWE-22"],"vendors":[],"products":[],"references":[{"url":"https://www.svenbluege.de/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}