Medium severityNVD Advisory· Published Aug 27, 2026· Updated Aug 28, 2026
CVE-2026-77989
CVE-2026-77989
Description
Joomla Extension - joomlaeventmanager.net - Reflected XSS via the PDF export link in Joomla Events Manager < 5.0.1 - buildCurrentPdfLink copies the current request query string into the PDF button URL, and pdfbutton() echoes it unescaped, leading to an reflected XSS vector.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <5.0.1
Patches
Vulnerability mechanics
References
1News mentions
1- Joomla Extensions: 25 Vulnerabilities Including Critical RCE, SQLi, and XSS Disclosed TogetherVypr Intelligence · Aug 28, 2026