Description
Joomla Extension - icagenda.com - Unauthenticated SQL injection in iCagenda < 4.0.0-4.0.11 - Unauthenticated SQL injection in mod_icagenda_calendar (iCagenda), reachable via com_ajax with no session, token or account.
Published: 2026-08-14
Score: 9.2 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an unauthenticated SQL injection in the iCagenda extension for Joomla, allowing an attacker to execute arbitrary SQL commands via the com_ajax endpoint without a session, token, or account. This flaw, identified as CWE‑89, can lead to unauthorized read, modification, or deletion of database contents, potentially giving attackers full access to sensitive data or enabling further attacks that compromise the affected system.

Affected Systems

The issue affects the iCagenda extension for Joomla distributed by icagenda.com. All installations using version 4.0.0 through 4.0.11 are vulnerable; versions prior to 4.0.0 and 4.0.12 and later contain the fix.

Risk and Exploitability

The CVSS score of 9.2 marks this flaw as critical, and although EPSS data is not available, the lack of the need for authentication makes exploitation highly feasible from any internet‑connected Joomla site hosting the vulnerable component. The vulnerability is not listed in the CISA KEV catalog, but the high severity and wide attack surface call for urgent remediation.

Generated by OpenCVE AI on August 14, 2026 at 21:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade iCagenda extension to version 4.0.12 or newer
  • Restrict access to the com_ajax endpoint so it requires user authentication or valid tokens
  • Apply additional input validation or use Joomla’s built-in security mechanisms to sanitize AJAX inputs

Generated by OpenCVE AI on August 14, 2026 at 21:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
Link Providers
https://www.icagenda.com/ cve-icon cve-icon
History

Fri, 14 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Icagenda.com
Icagenda.com icagenda Extension For Joomla
Vendors & Products Icagenda.com
Icagenda.com icagenda Extension For Joomla

Fri, 14 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
Description Joomla Extension - icagenda.com - Unauthenticated SQL injection in iCagenda < 4.0.0-4.0.11 - Unauthenticated SQL injection in mod_icagenda_calendar (iCagenda), reachable via com_ajax with no session, token or account.
Title Joomla Extension - icagenda.com - Unauthenticated SQL injection in iCagenda < 4.0.0-4.0.11
Weaknesses CWE-89
References
Metrics cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:L/SC:H/SI:H/SA:H'}


Subscriptions

Icagenda.com Icagenda Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-08-14T20:02:34.729Z

Reserved: 2026-07-29T14:01:47.235Z

Link: CVE-2026-67365

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-14T20:16:55.850

Modified: 2026-08-14T20:16:55.850

Link: CVE-2026-67365

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T21:30:04Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')