SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-75948

HIGH · CVSS 8.6 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-08-20 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The iCagenda extension for Joomla versions 4.0.8 to 4.0.12 is vulnerable to an authenticated stored cross-site scripting (XSS) attack through the "Submit an Event" form, where the `image` and `file` fields are improperly handled as raw strings without necessary HTML-attribute escaping. This flaw allows attackers with authenticated access to inject malicious scripts, potentially compromising user sessions and data integrity. Joomla administrators and developers using affected versions should prioritize patching this vulnerability to mitigate risks associated with XSS attacks.

CVE
CVE-2026-75948
Severity
HIGH
CVSS
8.6
EPSS
0.23%

Original NVD Description

Joomla Extension - icagenda.com - Authenticated Stored XSS in iCagenda 4.0.8 to 4.0.12 - The frontend "Submit an Event" form stores the `image` and `file` fields as raw strings with no output-side HTML-attribute escaping.