OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-97164

HIGH · CVSS 7 EPSS 0.31%

Source: NVD + CISA KEV + EPSS · Published 2026-09-27 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

The Event Gallery extension for Joomla versions prior to 6.5.0 is vulnerable to authenticated arbitrary path deletion through the `clear cache` task, allowing attackers to recursively delete any directories writable by the web server using the `images` parameter. This could lead to significant data loss and disruption of service for affected Joomla installations. Web administrators and security teams managing Joomla sites with this extension should prioritize patching to mitigate potential exploitation.

CVE
CVE-2026-97164
Severity
HIGH
CVSS
7
EPSS
0.31%

Original NVD Description

Joomla Extension - svenbluege.de - Authenticated arbitrary path deletion in `clear cache` task in Event Gallery extension < 6.5.0 - Using the `images` parameter of the `cache.process` task, you can recursively delete any directories that the web server is authorized to write to.