CVE-2026-48939
EUVD-2026-3810920.06.2026, 13:16
A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| joomlic | icagenda | 3.2.1 ≤ 𝑥 < 3.9.15 |
| joomlic | icagenda | 4.0.0 ≤ 𝑥 < 4.0.8 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References