CVE-2026-78071: Joomla Extension - digital-peak.com - Authenticated, privileged stored XSS in DP Calendar 7.0.0-8.19.5, 9.0.0-10.12.0
Published Aug 28, 2026
·Updated
Joomla Extension - digital-peak.com - Authenticated, privileged stored XSS in DP Calendar 7.0.0-8.19.5, 9.0.0-10.12.0 - Location title is rendered in data attribute without escaping leads to XSS, needs create permission in DPCalendar.
Affected Software
1 affected component
Joomla Extension - digital-peak.com - DP Calendar>=7.0.0<=8.19.5, >=9.0.0<=10.12.0
Event History
Aug 28, 2026
CVE Published
via MITRE·07:49 AM
Data Sourced
via MITRE·07:49 AM
DescriptionWeakness
Data Sourced
via NVD·12:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An attacker needs an authenticated account with permission to create content in DPCalendar. This is therefore primarily relevant where untrusted or lower-trust users have DPCalendar create permission.
2
Which releases are affected?
DP Calendar versions 7.0.0 through 10.11.2 are affected.
3
What input triggers the stored XSS?
The issue occurs when a location title is rendered into a data attribute without escaping. An authorized user can supply a crafted location title that is later rendered to other users.