SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-58149

MEDIUM · CVSS 5.3 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-07-17 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The Events Booking extension for Joomla versions prior to 5.8.0 is susceptible to an unauthenticated user enumeration vulnerability, enabling attackers to extract usernames and email addresses of accounts. This exposure can facilitate targeted attacks, such as phishing or credential stuffing. Joomla site administrators using this extension should prioritize patching to mitigate the risk of user data compromise.

CVE
CVE-2026-58149
Severity
MEDIUM
CVSS
5.3
EPSS
0.21%

Original NVD Description

Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0 - The Joomla extension Events Booking is vulnerable to an unauthenticated user enumeration that allows to retrieve account usernames and email addresses.