AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-14T21:17:56.807Z and has not been modified since then. The icagenda Joomla Extension has a potential ACL bypass vulnerability allowing arbitrary user enumeration. A backend operator with access scoped to `com_icagenda` only could enumerate Joomla user profiles. The vulnerability has a CVSS score of [truncated]
Authenticated SQL injection vulnerability in iCagenda Joomla Extension version < 2.0.0-4.0.11 allows backend operators with permissions to access iCagenda to inject SQL. This vulnerability has a high CVSS score of 8.6, indicating a high severity level. The vulnerability is caused by unescaped numeric filters in the iCagenda extension, potentially leading to data breaches or system compromise. Evidence fro [truncated]
The CVE-2026-67365 record details an unauthenticated SQL injection vulnerability in the Joomla Extension icagenda.com, specifically in versions prior to 4.0.0-4.0.11. This vulnerability is reachable via com_ajax without requiring a session, token, or account, posing a critical risk to affected systems. Administrators and users of Joomla Extension icagenda.com, as well as security teams responsible for vul [truncated]
Known exploitedicagenda.comCVE published 2026-07-10
The CVE-2026-48939 vulnerability in iCagenda allows for unrestricted upload of files with dangerous types, posing a critical risk. Defenders should assess exposure, prioritize remediation, and verify inventory for potential compromise. This vulnerability, listed in the CISA Known Exploited Vulnerabilities catalog, has a CVSS score of 10, indicating high risk. The vulnerability affects iCagenda installatio [truncated]