CVE-2026-48939: iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2026-07-10. EPSS: 20.1% chance of exploitation in the next 30 days.

A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.

Affected products

  • Joomlic iCagenda: from 3.2.1, before 3.9.15 (fixed in 3.9.15); from 4.0.0, before 4.0.8 (fixed in 4.0.8)

Published 2026-06-20. Last modified 2026-07-11.