icagenda has a security flaw
iCagenda's event-planning software has a flaw that lets attackers upload malicious files. Attackers can then run their own code on your server, which can steal data or take control.
- Severity
- CriticalCVSS 3.1 ยท 9.8
- Fix
- Fixed in 3.9.15Fix recorded on Aug 26, 2026
- Affected versions
- 3.2.1-4.0.7
- Weakness
- CWE-434Unrestricted Upload of Dangerous File Type
- Exploit likelihood
- 20% in 30 daysEPSS, higher than 97% of known flaws
- Affects
- iCagenda extension for Joomla
- Exploited
- Yes, in the wildListed by CISA
- Added to CISA list
- Jul 10, 2026
- Federal fix deadline
- Jul 13, 2026
How it works
Attackers send a malicious file through iCagenda's event attachment feature, bypassing the normal file checks and uploading it directly to your server.
What to do
Check the installed icagenda version. This advisory applies to 3.2.1 to before 3.9.15 or 4.0.0 to before 4.0.8.
Update icagenda to 3.9.15 or 4.0.8 or newer. Then verify the installed version.
Technical details
Affected software: iCagenda extension for Joomlaby icagenda.com
The source identifies icagenda as the affected product. Affected ranges: 3.2.1 to before 3.9.15, 4.0.0 to before 4.0.8. Fixed versions: 3.9.15, 4.0.8.
Severity breakdown
- Attack vector Network Requires network access to the vulnerable service
- Attack complexity Low Low complexity under the assessed conditions
- Privileges required None Attacker needs no account or login
- User interaction None No victim action needed
- Scope Unchanged Impact stays within the same security authority
- Confidentiality impact High Sensitive data can be exposed with serious impact
- Integrity impact High Protected data can be changed with serious impact
- Availability impact High The service can stop or suffer serious disruption
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Open in FIRST.org calculator