AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-71571

HIGH · CVSS 8.6

Source: NVD + CISA KEV + EPSS · Published 2026-08-14 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The iCagenda Joomla extension prior to version 2.0.0-4.0.11 is vulnerable to an authenticated SQL injection due to an unescaped numeric filter, allowing backend operators with appropriate permissions to execute arbitrary SQL queries. This vulnerability poses a high risk as it can lead to unauthorized data access or manipulation within the database. Organizations using this extension should prioritize patching to mitigate potential exploitation.

CVE
CVE-2026-71571
Severity
HIGH
CVSS
8.6
EPSS
N/A

Original NVD Description

Joomla Extension - icagenda.com - Authenticated SQL injection via unescaped numeric filter in iCagenda < 2.0.0-4.0.11 - Backend operators with permissions to access iCagenda could inject SQL.