Vendor
JoomGallery versions 4.3.0 and earlier are vulnerable to an access control bypass via the JSON view component, allowing unauthenticated attackers to retrieve protected image metadata and bypass password gates to download private content.