A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.
References
| Link | Resource |
|---|---|
| https://www.icagenda.com/ | Product |
| https://github.com/Polosss/By-Poloss..-..CVE-2026-48939 | Exploit Third Party Advisory |
| https://mysites.guru/blog/icagenda-zero-day-file-upload-rce/ | Third Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-48939 | US Government Resource |
| https://www.icagenda.com/docs/changelog/icagenda-3-9-15 | Release Notes |
| https://www.icagenda.com/docs/changelog/icagenda-4-0-8 | Release Notes |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-06-20 13:16
Updated : 2026-07-11 05:16
NVD link : CVE-2026-48939
Mitre link : CVE-2026-48939
CVE.ORG link : CVE-2026-48939
JSON object : View
Products Affected
joomlic
- icagenda
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type
