Authenticated SQL Injection in iCagenda Joomla Extension
CVE-2026-71571

8.6HIGH

Key Information:

Vendor
CVE Published:
14 August 2026

What is CVE-2026-71571?

The iCagenda Joomla extension is susceptible to an authenticated SQL injection vulnerability due to an unescaped numeric filter. Backend operators with appropriate permissions can exploit this flaw, injecting their own SQL queries into the database. This vulnerability could potentially result in unauthorized data access and manipulation by users who are authenticated but may not have sufficient rights to perform such actions. Users are advised to upgrade to the latest version to mitigate risks associated with this vulnerability.

Affected Version(s)

iCagenda extension for Joomla 4.0.0-4.0.11

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.