Description
Joomla Extension - joomdonation.com - Insecure default configuration Events Booking < 5.8.0 - The Joomla extension Events Booking prior version 5.8.0 did by default allow unauthenticated users to upload media assets.
Published: 2026-07-17
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Joomla extension Events Booking for joomdonation.com suffers from an insecure default configuration that allows unauthenticated users to upload media assets. Because the upload interface accepts arbitrary files, a threat actor could place executable scripts or malicious content on the server, leading to remote code execution or cross‑site scripting, depending on how the uploaded files are subsequently handled. This weakness is identified as CWE‑1188, reflecting an improper default configuration that permits unsafe operations for unauthenticated users.

Affected Systems

The vulnerability affects the joomdonation.com Events Booking extension for Joomla, specifically any installation running a version lower than 5.8.0. No additional vendor or product variants are listed beyond the primary extension.

Risk and Exploitability

The CVSS score of 9.8 marks this flaw as critical, and the EPSS score of less than 1% indicates that, while exploitation is currently rare, the potential impact is high. The extension is not present in the CISA KEV catalog. The attack vector is inferred to involve submitting a media file through the public upload interface; no special authentication or other conditions are required, making exploitation straightforward for an attacker with network access to the Joomla site.

Generated by OpenCVE AI on August 3, 2026 at 02:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Events Booking extension to version 5.8.0 or later.
  • Configure the extension to disable media uploads for unauthenticated users or raise the required access level to at least registered users.
  • Validate uploaded files on the server side and implement size and type restrictions to mitigate accidental or malicious uploads.

Generated by OpenCVE AI on August 3, 2026 at 02:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Joomdonation.com
Joomdonation.com events Booking Extension For Joomla
Vendors & Products Joomdonation.com
Joomdonation.com events Booking Extension For Joomla

Thu, 23 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Description The Joomla extension Events Booking prior version 5.8.0 did by default allow unauthenticated users to upload media assets. Joomla Extension - joomdonation.com - Insecure default configuration Events Booking < 5.8.0 - The Joomla extension Events Booking prior version 5.8.0 did by default allow unauthenticated users to upload media assets.

Mon, 20 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 17 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Description The Joomla extension Events Booking prior version 5.8.0 did by default allow unauthenticated users to upload media assets.
Title Joomla Extension - joomdonation.com - Insecure default configuration Events Booking < 5.8.0
Weaknesses CWE-1188
References

Subscriptions

Joomdonation.com Events Booking Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-07-23T14:59:25.448Z

Reserved: 2026-07-08T05:31:35.889Z

Link: CVE-2026-60024

cve-icon Vulnrichment

Updated: 2026-07-20T19:29:50.694Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T03:00:04Z

Weaknesses
  • CWE-1188

    Initialization of a Resource with an Insecure Default