Threat intelligence dashboard
CVE-2026-84048medium

Joomla Extension - joomgalleryfriends.net - Unauthenticated arbitrary file upload via the TUS endpoint in JoomGallery < 4.4.1

Joomla Extension - joomgalleryfriends.net - Unauthenticated arbitrary file upload via the TUS endpoint in JoomGallery < 4.4.1 - The TUS endpoint allows arbitrary file uploads, however neither file name nor file extension are under attacker control. Code execution requires non-standard server configuration.

Risk score

6.3

CVSS 4.0

Vendor
joomgalleryfriends.net
Product
JoomGallery extension for Joomla
CWE
CWE-284
Published
Sep 15, 2026
Updated
Sep 16, 2026
CISA KEV
Not flagged

Affected products and versions

JoomGallery extension for Joomla

joomgalleryfriends.net

Version / rangeStatusType
4.0.0-4.4.1affected

Technical metrics

6.3

CVSS 4.0

Severity
medium
Source
Joomla
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:A