CVE-2026-48939: iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability

A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.
CVE-2026-48939CVSS 10.0CISA KEVWeb

CVE-2026-48939: iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability

A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.

CVSS
10.0 CRITICAL
EPSS
97.64%
Known exploited
yes
Product
iCagenda

What is known

A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.

Sources

Security newsletter

Get new CVE alerts before they become an incident

We send selected infrastructure threats in English, with practical notes for DataHouse environments.

  • DataHouse: server administration and secure cloud
  • Hostilla.pl: hosting and mail services
  • SecDNS.pl: free DNS security layer