Description
Joomla Extension - digital-peak.com - Unauthenticated blind SQL injection in DP Calendar 8.18.0 - 10.11.2 - The Joomla extension DP Calendar is vulnerable to an unauthenticated SQL injection.
Published: 2026-07-15
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The DP Calendar extension for Joomla contains an unauthenticated blind SQL injection vulnerability that affects versions 8.18.0 through 10.11.2. When an attacker supplies crafted input to the extension’s unprotected parameters, the application directly injects the input into an SQL statement without proper sanitization. This flaw, identified as CWE-89, allows the attacker to read data from the underlying database, potentially exposing all stored persistent information.

Affected Systems

Affecting Joomla sites that use the digital‑peak.com DP Calendar component, specifically versions 8.18.0 through 10.11.2. Any site that has enabled this component and has not applied later patches remains vulnerable.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity, while the EPSS score of <1% reflects a low probability of exploitation in the wild as of the latest data. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that because the bug is unauthenticated, an attacker only needs to send HTTP requests to the vulnerable page; no credentials or privileged access are required. The lack of explicit exploitation details in the description means that the precise ease of exploitation is uncertain, yet the high severity suggests developers should treat it as a priority threat.

Generated by OpenCVE AI on August 3, 2026 at 03:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the DP Calendar extension to a version newer than 10.11.2; if no update is available, disable or remove the extension from the site.
  • Restrict access to the extension’s pages by applying Joomla’s ACL or web‑server rules so that only privileged users can reach them.
  • Enable detailed logging and regularly review logs for unusual SQL patterns or repeated failed queries that could indicate exploitation attempts.

Generated by OpenCVE AI on August 3, 2026 at 03:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Digital-peak
Digital-peak dp Calendar For Joomla
Vendors & Products Digital-peak
Digital-peak dp Calendar For Joomla

Thu, 23 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Description The Joomla extension DP Calendar is vulnerable to an unauthenticated SQL injection. Joomla Extension - digital-peak.com - Unauthenticated blind SQL injection in DP Calendar 8.18.0 - 10.11.2 - The Joomla extension DP Calendar is vulnerable to an unauthenticated SQL injection.

Wed, 15 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
References

Wed, 15 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 15 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Description The Joomla extension DP Calendar is vulnerable to an unauthenticated SQL injection.
Title Joomla Extension - digital-peak.com - Unauthenticated blind SQL injection in DP Calendar 8.18.0 - 10.11.2
Weaknesses CWE-89
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Digital-peak Dp Calendar For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-07-23T14:56:19.709Z

Reserved: 2026-06-25T16:55:04.094Z

Link: CVE-2026-57831

cve-icon Vulnrichment

Updated: 2026-07-15T12:32:01.174Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T03:15:05Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')