SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-60025

HIGH · CVSS 8.8 EPSS 0.13%

Source: NVD + CISA KEV + EPSS · Published 2026-07-17 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The Events Booking extension for Joomla versions prior to 5.8.0 is vulnerable due to a frontend file upload endpoint that lacks proper CSRF protection, allowing attackers to exploit this weakness for user enumeration. This vulnerability could lead to unauthorized access or manipulation of user data, posing a significant risk to affected Joomla installations. Organizations using this extension should prioritize updating to version 5.8.0 or later to mitigate potential security threats.

CVE
CVE-2026-60025
Severity
HIGH
CVSS
8.8
EPSS
0.13%

Original NVD Description

Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0 - The Joomla extension Events Booking prior version 5.8.0 had an frontend file upload endpoint that lacked CSRF protection.