CVE-2017-20267: Joomla! Calendar Planner

High severity, CVSS 8.2. EPSS: 0.5% chance of exploitation in the next 30 days.

Joomla! Component Calendar Planner 1.0.1 contains an SQL injection vulnerability that allows unauthenticated attackers to inject SQL commands through the category_id parameter. Attackers can send GET requests to the events view with malicious SQL code in the category_id parameter to extract sensitive database information.

Affected products

  • Joomla! Calendar Planner: version 1.0.1 only

Published 2026-06-19. Last modified 2026-08-19.