CVE-2026-77990: Joomla Extension - joomlaeventmanager.net - Attendee lists readable by any logged-in user in Joomla Event Manager < 5.0.1
Published Aug 27, 2026
·Updated
Joomla Extension - joomlaeventmanager.net - Attendee lists readable by any logged-in user in Joomla Event Manager < 5.0.1 - A non-manager can therefore read attendee names, usernames, registration dates and statuses for events they do not manage, including lists belonging to unpublished events.
Affected Software
1 affected component
Joomla Event Manager Joomla Event Manager<5.0.1
Event History
Aug 27, 2026
CVE Published
via MITRE·05:47 AM
Data Sourced
via MITRE·05:47 AM
DescriptionWeakness
Data Sourced
via NVD·06:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
Any authenticated Joomla user who is not an event manager can read attendee lists for events they do not manage, including unpublished events.
2
What information may be exposed?
Exposed attendee-list data includes attendee names, usernames, registration dates, and registration statuses.
3
Which installations are affected?
Joomla Event Manager versions earlier than 5.0.1 are affected.