CVE-2026-66917 HIGH

CVE-2026-66917: Joomla Extension - joomgalleryfriends.net - Stored XSS in JoomGallery < 4.4.0

Vendor Joomgalleryfriends.net
Product JoomGallery extension for Joomla
Weakness CWE-79 · XSS
Published August 22, 2026
Last update August 22, 2026

CVSS base score

8.6/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Joomla Extension - joomgalleryfriends.net - Stored XSS in JoomGallery < 4.4.0 - An authenticated, privileged can store an XSS payload in any image causing JS execution in every visitor's browser.

Explanation of Vulnerability in Simple Terms

02Summary

JoomGallery extension for Joomla versions 4.0.0 through 4.3.0 contains a cross-site scripting (XSS) vulnerability that allows high-privileged users to inject malicious scripts. An attacker with administrative or elevated permissions can craft input that executes JavaScript in the browsers of other site visitors, potentially compromising user sessions or stealing sensitive data.

What an attacker can do

03Attacker Capabilities

Inject and execute malicious JavaScript in other users' browsers via the JoomGallery interface.

Potential impact on your site

04Site Impact

Compromised admin accounts can inject scripts affecting all site visitors, risking session hijacking and data theft.

Conditions required to exploit

05Prerequisites

Attacker must have high-level privileges (admin or equivalent role) on the Joomla site.

Key dates

06Disclosure timeline

August 22, 2026 CVE published
August 22, 2026 Record updated

Related vulnerabilities

08Related CVE