CVE-2026-75948: Joomla Extension - icagenda.com - Authenticated Stored XSS in iCagenda 4.0.8 to 4.0.12
Joomla Extension - icagenda.com - Authenticated Stored XSS in iCagenda 4.0.8 to 4.0.12 - The frontend "Submit an Event" form stores the image and file fields as raw strings with no output-side HTML-attribute escaping.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated user who can access the frontend "Submit an Event" form can submit malicious values in the image or file fields. Exploitation depends on a victim later viewing a page that renders those stored values.
Which installations are affected?
The affected versions are iCagenda 4.0.8 through 4.0.12. The issue concerns the frontend event-submission functionality and its image and file fields.
What is the immediate mitigation if an update is not available?
Restrict access to the frontend "Submit an Event" form to trusted authenticated users, or disable that submission functionality. Review existing submitted events for untrusted content in the image and file fields.