You need to be logged in to post in the forum - Log In

An active JCE Pro Subscription is required to post in the forum - Buy a Subscription

Support is currently Offline

Official support hours
Monday to Friday
09:00 - 17:00 Europe/London (BST)

Please create a new Ticket and we will get back to you as soon as we can.

#117652 Mediabox gallery not displaying after the latest update

Posted in ‘Mediabox’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Latest post by SNCEP 86 on Monday, 20 April 2026 18:02 BST

SNCEP 86

Our observation:

Our gallery is no longer displayed on all pages of our website.https://www.sn-cep-86.fr/fabricant-de-mobilier/

The images no longer appear for insertion into the article. 

The plugin settings have changed.  

Sincerely  Auguste Pineau webmaster Sncep86

Attachments

Ryan

There appear to be a number of Content Security Policy errors on the site, that may be causing javascript code from being executed.

I don't see any specific errors related to MediaBox, and the scripts are loading correctly.

Ryan Demmer

Lead Developer / CEO / CTO

Just because you're not paranoid doesn't mean everybody isn't out to get you.

SNCEP 86

Thank you for your response.

We are using:

- the Topaz Gantry template https://updates.gantry.org/5.0/joomla/pkg_gantry5.xml Site Pack 5.5.19
- and the currently installed Joomla! version is "5.3.0"

My question: How can I find the site's content security policy, which might prevent the execution of JavaScript code?

Thank you in advance for your help.

Ryan

I misunderstood the issue in your original post.

Please send me a login - https://www.joomlacontenteditor.net/contact/site-login

Ryan Demmer

Lead Developer / CEO / CTO

Just because you're not paranoid doesn't mean everybody isn't out to get you.

Ryan

The issue in your first screenshot, and the gallery issue in the front-end are almost certainly caused by the Content-Security-Policy settings on your site, which may have been set in the htaccess file.

For example:

Content-Security-Policy: The page’s settings blocked an inline script (script-src-elem) from being executed because it violates the following directive: “script-src 'self'”. Consider using a hash ('sha256-5rQUivOqIuARSytHODLyLgOpat5/a1G7W34410CZrf8=') or a nonce.

and

 Content-Security-Policy: The page’s settings blocked an event handler (script-src-attr) from being executed because it violates the following directive: “script-src 'self'”. Consider using a hash ('sha256-2rvfFrggTCtyF5WOiTri1gDS8Boibj4Njn0e+VCBmDI=') together with 'unsafe-hashes'. Source: return false;

Ryan Demmer

Lead Developer / CEO / CTO

Just because you're not paranoid doesn't mean everybody isn't out to get you.

SNCEP 86

After examining the Infomaniak and Joomla .htaccess files, I don't see these lines with their code, like : ..../....Consider using a hash ('sha256-5rQUivOqIuARSytHODLyLgOpat5/a1G7W34410CZrf8=') or a nonce.

've explored another avenue: when examining the following code, the default media directory, `images`, isn't being used, but rather the media directory named `1`..
See these links:

<td><a href="https://www.joomlacontenteditor.net/1/produits/agencement-espaces-commerciaux/agencement-restaurant-5.jpg" target="_blank" type="image/jpeg" class="jcepopup zoom-right" title="Agencement de restaurant" data-rokbox-caption="Agencement de restaurant :: espace de restauration" data-rokbox="1" data-mediabox="1" data-mediabox-title="Agencement de restaurant"><img src="https://www.joomlacontenteditor.net/1/produits/agencement-espaces-commerciaux/thumbnails/thumb_agencement-restaurant-5.jpg" alt="agencement restaurant 5" width="253" height="190"></a><br>&nbsp;</td>

See these links: [links to links]. I unsuccessfully added `1` to the `.../...` path in the Extended Image Manager and other JCE MediaBox `.../...` paths.

 

I don't know what else to do, so thank you very much for your help.


Ryan

After examining the Infomaniak and Joomla .htaccess files, I don't see these lines with their code, like :

It won't specifically look like this, but if set in your htaccess file, might look something like this:

Header always set Content-Security-Policy "script-src 'self';"

This is very minimal and does not allow for inline javascript, which is what is being blocked by the Content Security Policy, causing the issues.

If it is not set in your htaccess file, it might be set at the server level. you can try and override this by adding the following to your htaccess file (usually better at the top):

Header unset Content-Security-Policy
Header add Content-Security-Policy "script-src 'self' 'unsafe-inline';"

Ryan Demmer

Lead Developer / CEO / CTO

Just because you're not paranoid doesn't mean everybody isn't out to get you.

SNCEP 86

Great! The Joomla article gallery managed with JCEMediabox, placed in the Gantry carousel module and the Topaz template, is working again thanks to your advice.

Before closing this ticket, if you have a minute, could you tell me what you know about the technical impact of Rocketthemes' closure on the Joomla community?

Auguste PINEAU  site :  https://www.sn-cep-86.fr/