Impact
The DP Calendar extension for Joomla contains an unauthenticated blind SQL injection vulnerability that affects versions 8.18.0 through 10.11.2. When an attacker supplies crafted input to the extension’s unprotected parameters, the application directly injects the input into an SQL statement without proper sanitization. This flaw, identified as CWE-89, allows the attacker to read data from the underlying database, potentially exposing all stored persistent information.
Affected Systems
Affecting Joomla sites that use the digital‑peak.com DP Calendar component, specifically versions 8.18.0 through 10.11.2. Any site that has enabled this component and has not applied later patches remains vulnerable.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity, while the EPSS score of <1% reflects a low probability of exploitation in the wild as of the latest data. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that because the bug is unauthenticated, an attacker only needs to send HTTP requests to the vulnerable page; no credentials or privileged access are required. The lack of explicit exploitation details in the description means that the precise ease of exploitation is uncertain, yet the high severity suggests developers should treat it as a priority threat.
OpenCVE Enrichment