CVE-2026-100747
— UNSCOREDPublished 2026-09-27 · Updated 2026-09-29
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
Joomla Extension - svenbluege.de - CSRF in image upload in Event Gallery extension < 6.5.0 - Due to lack of an CSRF token check, a third-party site can upload files to an event and overwrite existing files with the same name.
Weaknesses
CWE-352
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- CRITICALCVE-2025-15399
- MEDIUMCVE-2026-100524PoC
- MEDIUMCVE-2026-100712PoC
- UNSCOREDCVE-2026-100748
- UNSCOREDCVE-2026-100749
- MEDIUMCVE-2026-100873PoC
- MEDIUMCVE-2026-101093PoC
- MEDIUMCVE-2026-16613
Related by shared AI tags and CWE weakness class. Browse the full archive.