VYPR
Vendor

ICagenda

Products
1
CVEs
2
Across products
2
Status
Private

Products

1

Recent CVEs

2
  • CVE-2026-48939CriKEVJun 20, 2026
    risk 0.78cvss 9.8epss 0.20

    A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.

  • CVE-2026-67365CriAug 14, 2026
    risk 0.60cvss epss 0.00

    Joomla Extension - icagenda.com - Unauthenticated SQL injection in iCagenda < 4.0.0-4.0.11 - Unauthenticated SQL injection in mod_icagenda_calendar (iCagenda), reachable via com_ajax with no session, token or account.