CVE-2026-67366: Joomla Extension - icagenda.com - CSRF on frontend registration actions in iCagenda < 2.0.0-4.0.11
Published Aug 14, 2026
·Updated
Joomla Extension - icagenda.com - CSRF on frontend registration actions in iCagenda < 2.0.0-4.0.11 - Multiple state changing operations in the frontend are callable without a CSRF token check.
Affected Software
1 affected component
icagenda.com iCagenda<2.0.0-4.0.11
Event History
Aug 14, 2026
CVE Published
via MITRE·08:08 PM
Data Sourced
via MITRE·08:08 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-67366?
The severity of CVE-2026-67366 is rated at 35, indicating a moderate risk level.
2
How do I fix CVE-2026-67366?
To fix CVE-2026-67366, upgrade iCagenda to version 2.0.0-4.0.11 or higher, which includes patches for the CSRF vulnerability.
3
What type of vulnerability is CVE-2026-67366?
CVE-2026-67366 is a Cross-Site Request Forgery (CSRF) vulnerability affecting frontend registration actions in iCagenda.
4
Are all versions of iCagenda vulnerable to CVE-2026-67366?
Yes, all versions of iCagenda prior to 2.0.0-4.0.11 are vulnerable to CVE-2026-67366.
5
What are the potential impacts of CVE-2026-67366?
The potential impacts of CVE-2026-67366 include unauthorized state changes in the frontend due to the lack of CSRF token checks.