Каталог CVE

Расширение: iCagenda

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Сбросить

Найдено: 6

Расширение: iCagenda
Высокая CVSS 8.6

CVE-2026-75948

РасширениеiCagenda
Разработчикicagenda.com

Authenticated Stored XSS in iCagenda 4.0.8 to 4.0.12 - The frontend "Submit an Event" form stores the `image` and `file` fields as raw strings with no output-side HTML-attribute escaping.

20.08.2026 Требует внимания
Средняя CVSS 5.1

CVE-2026-71570

Разработчикicagenda.com

ACL bypass allowing arbitrary user enumeration < 2.0.0-4.0.11 - A backend operator granted access scoped to `com_icagenda` only could enumerate Joomla user profiles.

14.08.2026 Активна
Средняя CVSS 5.3

CVE-2026-67366

Разработчикicagenda.com

CSRF on frontend registration actions in iCagenda < 2.0.0-4.0.11 - Multiple state changing operations in the frontend are callable without a CSRF token check.

14.08.2026 Активна
Высокая CVSS 8.6

CVE-2026-71571

Разработчикicagenda.com

Authenticated SQL injection via unescaped numeric filter in iCagenda < 2.0.0-4.0.11 - Backend operators with permissions to access iCagenda could inject SQL.

14.08.2026 Требует внимания
Критическая CVSS 9.2

CVE-2026-67365

Разработчикicagenda.com

Unauthenticated SQL injection in iCagenda < 4.0.0-4.0.11 - Unauthenticated SQL injection in mod_icagenda_calendar (iCagenda), reachable via com_ajax with no session, token or account.

14.08.2026 Требует внимания
Критическая CVSS 10.0

CVE-2026-48939

РасширениеJoomlic Icagenda
Разработчикicagenda

A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.

20.06.2026 Требует внимания