CVE-2026-48939

A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:joomlic:icagenda:*:*:*:*:-:joomla\!:*:*
cpe:2.3:a:joomlic:icagenda:*:*:*:*:-:joomla\!:*:*

History

No history.

Information

Published : 2026-06-20 13:16

Updated : 2026-07-11 05:16


NVD link : CVE-2026-48939

Mitre link : CVE-2026-48939

CVE.ORG link : CVE-2026-48939


JSON object : View

Products Affected

joomlic

  • icagenda
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type