CVE-2018-7717: Kubik-Rubik Simple Image Gallery Extended

Medium severity, CVSS 6.1. EPSS: 0.7% chance of exploitation in the next 30 days.

The htmlImageAddTitleAttribute function in sige.php in the Kubik-Rubik Simple Image Gallery Extended (SIGE) extension 3.2.3 for Joomla! has XSS via a crafted image header, as demonstrated by the Caption-Abstract header object in a JPEG file. This is fixed in 3.3.1.

Affected products

  • Kubik-Rubik Simple Image Gallery Extended: before 3.3.1 (fixed in 3.3.1)

Published 2018-03-05. Last modified 2026-06-17.