{"id":"CVE-2026-97165","published":"2026-09-27T12:17:12.127","lastModified":"2026-09-29T21:39:02.570","description":"Joomla Extension - svenbluege.de - Reflected XSS and open redirect in Event Gallery extension < 6.5.0 - The “return” parameter is base64-decoded and written to the “Back” link without being validated.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":["CWE-79","CWE-601"],"vendors":[],"products":[],"references":[{"url":"https://www.svenbluege.de/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}