What is CVE-2026-63047?
The Events Booking extension (versions 5.0.0-5.8.1) for Joomla, from joomdonation.com, contains an incorrect ACL check vulnerability that allows unauthorized download of invoice data. This leads to sensitive information exfiltration. Immediate update of the extension is recommended.
Azərbaycanca: Joomla üçün Events Booking (5.0.0-5.8.1) genişlənməsində səhv ACL yoxlanışı səbəbindən səlahiyyəti olmayan istifadəçilər faktura məlumatlarını əldə edə bilərlər. Bu, həssas məlumat sızmasına yol açır. Təcili olaraq genişlənməni ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863
FAQ2
Which Joomla extension is affected by CVE-2026-63047?
This vulnerability affects the Events Booking extension for Joomla, versions 5.0.0 through 5.8.1.
What data can an attacker access by exploiting CVE-2026-63047?
Due to an incorrect ACL check, an unauthorized user can download invoice data, leading to sensitive information exfiltration.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.