icagenda.com vulnerabilities
4 CVEs tracked
The iCagenda Joomla extension from icagenda.com appears in our reports with multiple critical vulnerabilities. These reports primarily affect versions prior to 2.0.0-4.0.11. Defenders should be alert to SQL injection risks outlined in CVE-2026-67365 and CVE-2026-71571, which are exploitable by both unauthenticated users and backend operators. Additionally, CVE-2026-67366 highlights a CSRF issue on frontend actions, while CVE-2026-71570 details an ACL bypass allowing unauthorized user enumeration. Unauthenticated attack vectors targeting the `mod_icagenda_calendar` module via `com_ajax` should be treated as a critical priority.
Azərbaycanca: Icagenda.com (iCagenda) Joomla komponenti kimi hesabatlarımızda bir neçə kritik boşluqla qeyd olunur. Hesabatlar əsasən 2.0.0-4.0.11 versiyasından əvvəlki məhsulları əhatə edir. Müdafiəçilər CVE-2026-67365 və CVE-2026-71571-ə əsasən, həm autentifikasiya olunmamış, həm də arxa panel operatorları tərəfindən istifadə edilə bilən SQL injection hücumlarına qarşı sayıq olmalıdır. Həmçinin, CVE-2026-67366 (CSRF) frontend əməliyyatlarında, CVE-2026-71570 isə ACL bypass vasitəsilə icazəsiz istifadəçi məlumatlarının əldə olunması riski yaradır. Xüsusilə `mod_icagenda_calendar` moduluna yönəlmiş autentifikasiyası tələb olunmayan hücum vektorları kritik prioritet olmalıdır.
This vendor's CVEs4
This hub is built from skopnix's own reporting on icagenda.com: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.