Joomla 扩展 – joomlaeventmanager.net – Joomla Event Manager 5.0.1 之前版本中,参会者列表可被任何登录用户读取——因此,非管理员(非管理者)用户能够读取他们所不管理的事件的参会者姓名、用户名、注册日期及状态,甚至包括那些未发布事件相关的列表。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| joomlaeventmanager.net | JEM - Joomla Event Manager extension for Joomla | 1.0.0-5.0.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-77991 | 9.4 CRITICAL | Joomla Extension - joomlaeventmanager.net - Privileged remote code execution in Joomla Eve |
| CVE-2026-77034 | 6.9 MEDIUM | Joomla Extension - joomlaeventmanager.net - Unauthenticated article overwrite and force-pu |
| CVE-2026-77989 | 5.3 MEDIUM | Joomla Extension - joomlaeventmanager.net - Reflected XSS via the PDF export link in Jooml |
| CVE-2026-77035 | 5.1 MEDIUM | Joomla Extension - joomlaeventmanager.net - Cross-user event and venue takeover through fo |
No comments yet