CVE-2026-67366: Icagenda.com iCagenda Extension For Joomla
Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.
Joomla Extension - icagenda.com - CSRF on frontend registration actions in iCagenda < 2.0.0-4.0.11 - Multiple state changing operations in the frontend are callable without a CSRF token check.
Affected products
- Icagenda.com iCagenda Extension For Joomla: version 2.0.0-4.0.11 only
Published 2026-08-14. Last modified 2026-08-26.