CVE-2026-78071: Joomla Extension - digital-peak.com - Authenticated, privileged stored XSS in DP Calendar 7.0.0 - 10.11.2
Published Aug 28, 2026
·Updated
Joomla Extension - digital-peak.com - Authenticated, privileged stored XSS in DP Calendar 7.0.0 - 10.11.2 - Location title is rendered in data attribute without escaping leads to XSS, needs create permission in DPCalendar.
Affected Software
1 affected component
Joomla Extension - digital-peak.com - DP Calendar>=7.0.0<=10.11.2
Event History
Aug 28, 2026
CVE Published
via MITRE·07:49 AM
Data Sourced
via MITRE·07:49 AM
DescriptionWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An attacker needs an authenticated account with permission to create content in DPCalendar. This is therefore primarily relevant where untrusted or lower-trust users have DPCalendar create permission.
2
Which releases are affected?
DP Calendar versions 7.0.0 through 10.11.2 are affected.
3
What input triggers the stored XSS?
The issue occurs when a location title is rendered into a data attribute without escaping. An authorized user can supply a crafted location title that is later rendered to other users.