Description
Joomla Extension - digital-peak.com - Authenticated, privileged blind SQL injection in DP Calendar 5.5.0 - 10.11.2 - Saving an article can trigger a blind SQL injection with content plugin, needs update permission for articles.
Published: 2026-08-28
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The DP Calendar extension for Joomla contains an authenticated, privileged blind SQL injection that is triggered when an article is saved with a content plugin. An attacker who holds the permission to update articles can inject SQL and read or modify arbitrary database contents, potentially elevating privileges or exfiltrating sensitive data.

Affected Systems

Vulnerable versions of the digital‑peak.com DP Calendar extension range from 5.5.0 to 10.11.2. Any site running these versions of the extension under Joomla and granting update rights to article users is subject to the fault, regardless of the site’s overall user base or deployment size.

Risk and Exploitability

With a CVSS score of 6.9 the flaw is classified as medium severity. The EPSS score is not published and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires a logged‑in user with article update privileges, meaning the threat surface is limited to trusted accounts. However, when those premises are met, an attacker can inject blind queries to extract or alter database records, compromising confidentiality and integrity.

Generated by OpenCVE AI on August 28, 2026 at 14:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the DP Calendar extension to the latest release available from digital‑peak.com
  • If an immediate update is impossible, remove or disable the content plugin that triggers the injection until the extension is patched
  • Restrict article update permissions so that only trusted administrators have the ability to modify articles, eliminating the privileged requirement for the attack

Generated by OpenCVE AI on August 28, 2026 at 14:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 28 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
Description Joomla Extension - digital-peak.com - Authenticated, privileged blind SQL injection in DP Calendar 5.5.0 - 10.11.2 - Saving an article can trigger a blind SQL injection with content plugin, needs update permission for articles.
Title Joomla Extension - digital-peak.com - Authenticated, privileged blind SQL injection in DP Calendar 5.5.0 - 10.11.2
Weaknesses CWE-89
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-08-28T15:09:54.356Z

Reserved: 2026-08-22T14:23:37.800Z

Link: CVE-2026-78070

cve-icon Vulnrichment

Updated: 2026-08-28T15:09:49.371Z

cve-icon NVD

Status : Deferred

Published: 2026-08-28T12:16:31.690

Modified: 2026-08-28T16:18:26.947

Link: CVE-2026-78070

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T14:15:04Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')