๐Ÿ” CVE Alert

CVE-2026-48939

UNKNOWN 0.0 โš ๏ธ CISA KEV

Joomla Extension - icagenda.com - Remote Code Execution in iCaganda extension for Joomla < 4.0.8/3.9.15

CVSS Score
0.0
EPSS Score
0.6%
EPSS Percentile
43th

A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.

CWE CWE-434
Vendor icagenda.com
Product icagenda extension for joomla
Published Jun 20, 2026
Last Updated Jul 11, 2026
โš ๏ธ Actively Exploited โ€” Act Now

Get instant alerts for icagenda.com icagenda extension for joomla

This vulnerability is actively exploited in the wild. Set up free real-time alerts so you're first to know about threats like CVE-2026-48939.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

icagenda.com / iCagenda extension for Joomla
3.2.1-4.0.7

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
icagenda.com: https://www.icagenda.com/ mysites.guru: https://mysites.guru/blog/icagenda-zero-day-file-upload-rce/ icagenda.com: https://www.icagenda.com/docs/changelog/icagenda-3-9-15 icagenda.com: https://www.icagenda.com/docs/changelog/icagenda-4-0-8 github.com: https://github.com/Polosss/By-Poloss..-..CVE-2026-48939 cisa.gov: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-48939

Credits

Phil Taylor