CyberRota Analysis
AI-GeneratedThe Events Booking extension for Joomla versions prior to 5.8.0 is susceptible to an unauthenticated user enumeration vulnerability, enabling attackers to extract usernames and email addresses of accounts. This exposure can facilitate targeted attacks, such as phishing or credential stuffing. Joomla site administrators using this extension should prioritize patching to mitigate the risk of user data compromise.
CVE
CVE-2026-58149
Severity
MEDIUM
CVSS
5.3
EPSS
0.21%
Original NVD Description
Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0 - The Joomla extension Events Booking is vulnerable to an unauthenticated user enumeration that allows to retrieve account usernames and email addresses.