CVE-2026-77989
EUVD-2026-6686227.08.2026, 06:17
Joomla Extension - joomlaeventmanager.net - Reflected XSS via the PDF export link in Joomla Events Manager < 5.0.1 - buildCurrentPdfLink copies the current request query string into the PDF button URL, and pdfbutton() echoes it unescaped, leading to an reflected XSS vector.
Awaiting analysis
This vulnerability is currently awaiting analysis.
References