Joomla 扩展 - icagenda.com - iCagenda < 2.0.0-4.0.11 版本在前端注册操作中存在 CSRF 漏洞 - 前端多个状态变更操作可在未进行 CSRF 令牌检查的情况下被调用。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| icagenda.com | iCagenda extension for Joomla | 2.0.0-4.0.11 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| icagenda.com | iCagenda extension for Joomla | 2.0.0-4.0.11 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-67365 | 9.2 CRITICAL | Joomla Extension - icagenda.com - Unauthenticated SQL injection in iCagenda < 4.0.0-4.0.11 |
| CVE-2026-71571 | 8.6 HIGH | Joomla Extension - icagenda.com - Authenticated SQL injection via unescaped numeric filter |
| CVE-2026-71570 | 5.1 MEDIUM | Joomla Extension - icagenda.com - ACL bypass allowing arbitrary user enumeration < 2.0.0-4 |
No comments yet