AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-67366

MEDIUM · CVSS 5.3

Source: NVD + CISA KEV + EPSS · Published 2026-08-14 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The iCagenda Joomla extension versions prior to 2.0.0-4.0.11 are vulnerable to cross-site request forgery (CSRF) attacks, allowing unauthorized users to perform state-changing operations on the frontend without proper token validation. This vulnerability could lead to unauthorized modifications or actions being executed on behalf of legitimate users. Joomla site administrators using affected versions should prioritize applying the update to mitigate potential exploitation risks.

CVE
CVE-2026-67366
Severity
MEDIUM
CVSS
5.3
EPSS
N/A

Original NVD Description

Joomla Extension - icagenda.com - CSRF on frontend registration actions in iCagenda < 2.0.0-4.0.11 - Multiple state changing operations in the frontend are callable without a CSRF token check.