CVE-2026-60025: Joomdonation.com Events Booking Extension For Joomla
High severity, CVSS 8.8. EPSS: 0.2% chance of exploitation in the next 30 days.
Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0 - The Joomla extension Events Booking prior version 5.8.0 had an frontend file upload endpoint that lacked CSRF protection.
Affected products
- Joomdonation.com Events Booking Extension For Joomla: version 1.0-5.8.0 only
Published 2026-07-17. Last modified 2026-07-23.