SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-66917

HIGH · CVSS 8.6 EPSS 0.47%

Source: NVD + CISA KEV + EPSS · Published 2026-08-22 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The JoomGallery extension prior to version 4.4.0 is vulnerable to stored cross-site scripting (XSS), allowing authenticated users with sufficient privileges to embed malicious JavaScript in images. This results in the execution of the payload in the browsers of all visitors, potentially leading to session hijacking or data theft. Joomla administrators and users of the affected extension should prioritize updating to the latest version to mitigate this high-severity risk.

CVE
CVE-2026-66917
Severity
HIGH
CVSS
8.6
EPSS
0.47%

Original NVD Description

Joomla Extension - joomgalleryfriends.net - Stored XSS in JoomGallery < 4.4.0 - An authenticated, privileged can store an XSS payload in any image causing JS execution in every visitor's browser.