CVE-2026-75948
Joomla Extension - icagenda.com - Authenticated Stored XSS in iCagenda 4.0.8 to 4.0.12
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Joomla Extension - icagenda.com - Authenticated Stored XSS in iCagenda 4.0.8 to 4.0.12 - The frontend "Submit an Event" form stores the `image` and `file` fields as raw strings with no output-side HTML-attribute escaping.
| CWE | CWE-79 |
| Vendor | icagenda.com |
| Product | icagenda extension for joomla |
| Published | Aug 20, 2026 |
Stay Ahead of the Next One
Get instant alerts for icagenda.com icagenda extension for joomla
Be the first to know when new unknown vulnerabilities affecting icagenda.com icagenda extension for joomla are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
icagenda.com / iCagenda extension for Joomla
4.0.8-4.0.12
Credits
Akinlabi Omoogun of lulztigre.pw