Impact
The DP Calendar extension for Joomla contains a stored cross‑site scripting vulnerability from version 7.0.0 through 10.12.0. The Location title is rendered in a data attribute without escaping, allowing an authenticated user with Create permission to inject malicious scripts that are preserved and executed whenever the page is viewed.
Affected Systems
Any Joomla installation using the DP Calendar extension from digital-peak.com and running a supported release in either the 7.0.0-8.19.5 or 9.0.0-10.12.0 ranges is affected. No other products or versions are listed as impacted in the available data.
Risk and Exploitability
The CVSS score of 7.5 signifies a high severity rating. Exploitation requires authentication and the privileged Create role; therefore the impact is confined to individuals with those rights but the stored code runs in the context of every visitor to the calendar page. No KEV listing exists and the EPSS score is below 1%, indicating a low probability of exploitation. The vulnerability remains a serious concern for sites that delegate Create permissions widely.
OpenCVE Enrichment