CVE-2026-97164

Summary

Joomla Extension - svenbluege.de - Authenticated arbitrary path deletion in clear cache task in Event Gallery extension < 6.5.0 - Using the images parameter of the cache.process task, you can recursively delete any directories that the web server is authorized to write to.

Affected Software

VendorProductVersion RangeStatus
svenbluege.deEvent Gallery for Joomla1.0.0-6.0.0affected

Weaknesses

  • CWE-22: CWE-22 Improper Limitation of a Pathname to a Restricted Directory

References