Cross-Site Request Forgery in iCagenda Joomla Extension by icagenda.com
CVE-2026-67366

5.3MEDIUM

Key Information:

Vendor
CVE Published:
14 August 2026

What is CVE-2026-67366?

The iCagenda Joomla extension contains a vulnerability that allows multiple state-changing operations in the frontend to be executed without the necessary CSRF token validation. This lax security measure could enable attackers to exploit the system by tricking users into performing unintended actions, thereby compromising the integrity of the web application and potentially leading to unauthorized access or manipulation of the site's data.

Affected Version(s)

iCagenda extension for Joomla 2.0.0-4.0.11

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.