Authenticated Stored XSS in iCagenda Joomla Extension
CVE-2026-75948

8.6HIGH

Key Information:

Vendor
CVE Published:
20 August 2026

What is CVE-2026-75948?

The iCagenda Joomla extension has a vulnerability in its 'Submit an Event' form. The image and file fields are stored as raw strings, lacking necessary HTML-attribute escaping on the output side, which can lead to Authenticated Stored Cross-Site Scripting (XSS). This flaw enables attackers to inject malicious scripts that could execute in the context of the user's browser, potentially compromising user interactions and leading to data theft or session hijacking.

Affected Version(s)

iCagenda extension for Joomla 4.0.8-4.0.12

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Akinlabi Omoogun of lulztigre.pw
.