CVE-2018-7717: Kubik-Rubik Simple Image Gallery Extended
Medium severity, CVSS 6.1. EPSS: 0.7% chance of exploitation in the next 30 days.
The htmlImageAddTitleAttribute function in sige.php in the Kubik-Rubik Simple Image Gallery Extended (SIGE) extension 3.2.3 for Joomla! has XSS via a crafted image header, as demonstrated by the Caption-Abstract header object in a JPEG file. This is fixed in 3.3.1.
Affected products
- Kubik-Rubik Simple Image Gallery Extended: before 3.3.1 (fixed in 3.3.1)
Published 2018-03-05. Last modified 2026-06-17.