Joomla Extension - icagenda.com - Authenticated Stored XSS in iCagenda 4.0.8 to 4.0.12 - The frontend "Submit an Event" form stores the `image` and `file` fields as raw strings with no output-side HTML-attribute escaping.
CVSS
No CVSS.
References
| Link | Resource |
|---|---|
| https://www.icagenda.com/ |
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-20 08:16
Updated : 2026-08-26 16:35
NVD link : CVE-2026-75948
Mitre link : CVE-2026-75948
CVE.ORG link : CVE-2026-75948
JSON object : View
Products Affected
No product.
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
