Unauthenticated SQL Injection in Joomla Extension - iCagenda
CVE-2026-67365
9.2CRITICAL
What is CVE-2026-67365?
A security vulnerability exists in the iCagenda Joomla extension, which allows unauthenticated attackers to execute SQL injection attacks through the mod_icagenda_calendar. This flaw can be exploited via the com_ajax interface without requiring a user session or token, potentially compromising the integrity of the database and exposing sensitive data.
Affected Version(s)
iCagenda extension for Joomla 4.0.0-4.0.11
