CVE-2026-48939
Joomla Extension - icagenda.com - Remote Code Execution in iCaganda extension for Joomla < 4.0.8/3.9.15
CVSS Score
0.0
EPSS Score
0.6%
EPSS Percentile
43th
A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.
| CWE | CWE-434 |
| Vendor | icagenda.com |
| Product | icagenda extension for joomla |
| Published | Jun 20, 2026 |
| Last Updated | Jul 11, 2026 |
โ ๏ธ Actively Exploited โ Act Now
Get instant alerts for icagenda.com icagenda extension for joomla
This vulnerability is actively exploited in the wild. Set up free real-time alerts so you're first to know about threats like CVE-2026-48939.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
icagenda.com / iCagenda extension for Joomla
3.2.1-4.0.7
References
icagenda.com: https://www.icagenda.com/ mysites.guru: https://mysites.guru/blog/icagenda-zero-day-file-upload-rce/ icagenda.com: https://www.icagenda.com/docs/changelog/icagenda-3-9-15 icagenda.com: https://www.icagenda.com/docs/changelog/icagenda-4-0-8 github.com: https://github.com/Polosss/By-Poloss..-..CVE-2026-48939 cisa.gov: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-48939
Credits
Phil Taylor