What is CVE-2026-67365?
This CVE describes an unauthenticated SQL injection vulnerability in the iCagenda Joomla extension versions prior to 4.0.0-4.0.11. An attacker can exploit the `mod_icagenda_calendar` module through `com_ajax` without any session, token, or account. Immediate update to the latest version is strongly recommended.
Azərbaycanca: Bu CVE, iCagenda Joomla genişləndirməsinin 4.0.0-4.0.11 versiyalarında autentifikasiya olmadan SQL injection həssaslığını təsvir edir. Hücumçu `mod_icagenda_calendar` moduluna `com_ajax` vasitəsilə sorğu göndərərək məlumat bazasına icazəsiz giriş əldə edə bilər. Dərhal genişləndirməni son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: shared vendors: Joomla, icagenda.com
FAQ2
Which Joomla extension does CVE-2026-67365 affect?
CVE-2026-67365 affects the iCagenda Joomla extension versions 4.0.0 through 4.0.11.
How can an attacker exploit CVE-2026-67365?
An attacker can exploit this SQL injection by sending a request to the `mod_icagenda_calendar` module via `com_ajax` without any authentication, session token, or account.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.