CVE-2026-48939: iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability
Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2026-07-10. EPSS: 20.1% chance of exploitation in the next 30 days.
A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.
Affected products
- Joomlic iCagenda: from 3.2.1, before 3.9.15 (fixed in 3.9.15); from 4.0.0, before 4.0.8 (fixed in 4.0.8)
Published 2026-06-20. Last modified 2026-07-11.