Impact
The DP Calendar extension for Joomla contains a stored cross‑site scripting vulnerability from version 7.0.0 through 10.11.2. The title of a calendar item is placed inside a data attribute without escaping, allowing an authenticated user who has Create permission to inject malicious scripts that are preserved and executed whenever the page is viewed.
Affected Systems
Any Joomla installation using the DP Calendar extension from digital-peak.com and running a supported release between 7.0.0 and 10.11.2 is affected. No other products or versions are listed as impacted in the available data.
Risk and Exploitability
The CVSS score of 7.5 signifies a high severity rating. Exploitation requires authentication and the privileged Create role; therefore the impact is confined to individuals with those rights but the stored code runs in the context of every visitor to the calendar page. No KEV listing exists and an EPSS score is not provided, so current known exploitation activity is not documented. The vulnerability remains a serious concern for sites that delegate Create permissions widely.
OpenCVE Enrichment