SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-60024

CRITICAL · CVSS 9.8 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-07-17 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The Events Booking extension for Joomla, prior to version 5.8.0, is vulnerable due to its insecure default configuration that permits unauthenticated users to upload media assets. This flaw could lead to unauthorized access and potential exploitation of the web application, posing a critical risk to the integrity and security of the affected systems. Joomla administrators and users of the Events Booking extension should prioritize upgrading to version 5.8.0 or later to mitigate this vulnerability.

CVE
CVE-2026-60024
Severity
CRITICAL
CVSS
9.8
EPSS
0.30%

Original NVD Description

Joomla Extension - joomdonation.com - Insecure default configuration Events Booking < 5.8.0 - The Joomla extension Events Booking prior version 5.8.0 did by default allow unauthenticated users to upload media assets.