Description
Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0 - The Joomla extension Events Booking is vulnerable to an unauthenticated user enumeration that allows to retrieve account usernames and email addresses.
Published: 2026-07-17
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

User enumeration in the Events Booking extension for Joomla allows an unauthenticated attacker to retrieve account usernames and email addresses via publicly accessible endpoints. This information‑exposure vulnerability (CWE‑200) gives the attacker the ability to compile a list of users, which can be used for targeted phishing, password‑guessing attacks, or profiling, thereby compromising account confidentiality on the website.

Affected Systems

Developers and administrators running the Events Booking extension from joomdonation.com for Joomla are affected if their installation is any version earlier than 5.8.0. Version 5.8.0 and later contain a fix that removes the enumeration capability.

Risk and Exploitability

The CVSS score of 5.3 signals moderate severity. An EPSS score of less than 1 % indicates a very low likelihood of exploitation at present, and the flaw is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is an unauthenticated request to a public endpoint exposed by the extension (such as its registration or API page) that returns user details in its response. Remediation requires preventing such requests from revealing account information.

Generated by OpenCVE AI on August 3, 2026 at 02:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Events Booking extension to version 5.8.0 or newer.
  • If upgrading is not immediately feasible, block unauthenticated access to the extension’s public API or registration pages that expose user data.
  • Enable logging and monitoring of repeated enumeration attempts and apply rate limiting to the affected endpoints where possible.

Generated by OpenCVE AI on August 3, 2026 at 02:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Joomdonation.com
Joomdonation.com events Booking Extension For Joomla
Vendors & Products Joomdonation.com
Joomdonation.com events Booking Extension For Joomla

Thu, 23 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Description The Joomla extension Events Booking is vulnerable to an unauthenticated user enumeration that allows to retrieve account usernames and email addresses. Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0 - The Joomla extension Events Booking is vulnerable to an unauthenticated user enumeration that allows to retrieve account usernames and email addresses.

Mon, 20 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 17 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Description The Joomla extension Events Booking is vulnerable to an unauthenticated user enumeration that allows to retrieve account usernames and email addresses.
Title Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0
References

Subscriptions

Joomdonation.com Events Booking Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-07-23T14:56:50.809Z

Reserved: 2026-06-29T14:35:29.745Z

Link: CVE-2026-58149

cve-icon Vulnrichment

Updated: 2026-07-20T19:32:26.748Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T03:00:04Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor