Access Control Flaw in Events Booking Extension for Joomla by JoomlaDonation
CVE-2026-63047

Currently unrated

Key Information:

Vendor
CVE Published:
22 July 2026

What is CVE-2026-63047?

The Events Booking extension for Joomla versions prior to 5.0-5.8.1 lacks proper verification mechanisms, allowing unauthorized actors to access and download sensitive invoice information. This could lead to data exposure for users who rely on the extension for managing event registrations and related financial transactions.

Affected Version(s)

Events Booking extension for Joomla 5.0-5.8.1

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Phil Taylor
.