VYPR
Critical severity9.8CISA KEVNVD Advisory· Published Jun 20, 2026· Updated Jul 11, 2026

CVE-2026-48939

CVE-2026-48939

Description

A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2

Patches

Vulnerability mechanics

References

5

News mentions

6