VYPR

Events Booking

by Joomdonation.com

CVEs (3)

  • CVE-2026-63047HigJul 22, 2026
    risk 0.00cvss 7.5epss 0.00

    Joomla Extension - joomdonation.com - Invoice data exfiltration via incorrect ACL check in Events Booking 5.0.0-5.8.1 - The Joomla extension Events Booking prior version 5.0-5.8.1 did not properly verify that an actor is allowed to download invoice information.

  • CVE-2026-60025HigJul 17, 2026
    risk 0.00cvss 8.8epss 0.00

    Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0 - The Joomla extension Events Booking prior version 5.8.0 had an frontend file upload endpoint that lacked CSRF protection.

  • CVE-2026-58149MedJul 17, 2026
    risk 0.00cvss 5.3epss 0.00

    Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0 - The Joomla extension Events Booking is vulnerable to an unauthenticated user enumeration that allows to retrieve account usernames and email addresses.