Description
Joomla Extension - digital-peak.com - Authenticated, privileged blind SQL injection in DP Calendar 5.5.0 - 10.11.2 - Saving an article can trigger a blind SQL injection with content plugin, needs update permission for articles.
Published: 2026-08-28
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authenticated SQL injection enabling database compromise
Action: Patch now
AI Analysis

Impact

The DP Calendar extension for Joomla contains an authenticated, privileged blind SQL injection that is triggered when an article is saved with a content plugin. An attacker who holds the permission to update articles can inject SQL and read or modify arbitrary database contents, potentially elevating privileges or exfiltrating sensitive data.

Affected Systems

Vulnerable versions of the digital‑peak.com DP Calendar extension range from 5.5.0 to 10.11.2. Any site running these versions of the extension under Joomla and granting update rights to article users is subject to the fault, regardless of the site’s overall user base or deployment size.

Risk and Exploitability

With a CVSS score of 6.9 the flaw is classified as medium severity. The EPSS score is not published and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires a logged‑in user with article update privileges, meaning the threat surface is limited to trusted accounts. However, when those premises are met, an attacker can inject blind queries to extract or alter database records, compromising confidentiality and integrity.

Generated by OpenCVE AI on August 28, 2026 at 14:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the DP Calendar extension to the latest release available from digital‑peak.com
  • If an immediate update is impossible, remove or disable the content plugin that triggers the injection until the extension is patched
  • Restrict article update permissions so that only trusted administrators have the ability to modify articles, eliminating the privileged requirement for the attack

Generated by OpenCVE AI on August 28, 2026 at 14:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Digital-peak
Digital-peak dp Calendar For Joomla
Vendors & Products Digital-peak
Digital-peak dp Calendar For Joomla

Fri, 28 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 28 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
Description Joomla Extension - digital-peak.com - Authenticated, privileged blind SQL injection in DP Calendar 5.5.0 - 10.11.2 - Saving an article can trigger a blind SQL injection with content plugin, needs update permission for articles.
Title Joomla Extension - digital-peak.com - Authenticated, privileged blind SQL injection in DP Calendar 5.5.0 - 10.11.2
Weaknesses CWE-89
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Digital-peak Dp Calendar For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-08-29T04:36:03.852Z

Reserved: 2026-08-22T14:23:37.800Z

Link: CVE-2026-78070

cve-icon Vulnrichment

Updated: 2026-08-28T15:09:49.371Z

cve-icon NVD

Status : Deferred

Published: 2026-08-28T12:16:31.690

Modified: 2026-08-28T16:18:26.947

Link: CVE-2026-78070

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T14:00:03Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')