PatchSiren cyber security CVE debrief
CVE-2026-60024 joomdonation.com CVE debrief
The Joomla extension Events Booking prior version 5.8.0 did by default allow unauthenticated users to upload media assets. This CVE record was published on 2026-07-17T16:17:16.113Z and has not been modified since then. The vulnerability affects Joomla Events Booking extension, allowing unauthenticated users to upload media assets by default, potentially leading to malicious asset uploads.
- Vendor
- joomdonation.com
- Product
- Events Booking extension for Joomla
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-17
- Original CVE updated
- 2026-07-20
- Advisory published
- 2026-07-17
- Advisory updated
- 2026-07-20
Who should care
Users of Joomla Events Booking extension prior to version 5.8.0, operators, platform administrators, vulnerability management teams, and security teams should review and update their installations to prevent potential media asset uploads by unauthenticated users. They should also monitor for suspicious media asset uploads and review compensating controls for exposed systems.
Technical summary
The Events Booking extension for Joomla, prior to version 5.8.0, allowed unauthenticated users to upload media assets by default. This vulnerability could potentially be exploited to upload malicious assets, impacting the security of Joomla installations. Users of the extension should review and update their installations to prevent potential security risks.
Defensive priority
Medium
Recommended defensive actions
- Review and update Joomla Events Booking extension to version 5.8.0 or later
- Restrict media asset uploads to authenticated users
- Monitor for suspicious media asset uploads
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
Evidence notes
The CVE record and NVD entry provide limited information about the vulnerability. Further investigation and verification are necessary to fully understand the impact and scope of this vulnerability. The source details are limited, and defenders should verify the affected scope, severity, and vendor guidance. The CVE record was published on 2026-07-17T16:17:16.113Z and has not been modified since then.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-60024 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-60024
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-60024 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-60024
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://joomdonation.com/joomla-extensions/events-booking-joomla-events-registration.html
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.