SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-78070

MEDIUM · CVSS 6.9 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-08-28 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The DP Calendar extension for Joomla versions 5.5.0 to 10.11.2 is vulnerable to an authenticated, privileged blind SQL injection that can be exploited when saving an article with a content plugin, requiring users to have update permissions. Successful exploitation could allow attackers to manipulate the database, potentially leading to unauthorized data access or modification. Joomla administrators and users of the affected extension should prioritize applying updates to mitigate this vulnerability.

CVE
CVE-2026-78070
Severity
MEDIUM
CVSS
6.9
EPSS
0.27%

Original NVD Description

Joomla Extension - digital-peak.com - Authenticated, privileged blind SQL injection in DP Calendar 5.5.0 - 10.11.2 - Saving an article can trigger a blind SQL injection with content plugin, needs update permission for articles.