Security
Loading…

CVE-2026-48939

CRITICALCVSS 9.8Known Exploited
Description

iCagenda contains an unrestricted upload of file with dangerous type vulnerability that allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.

Timeline
Published:June 20th, 2026 1:16 PM
Last modified:July 11th, 2026 5:16 AM
Added to KEV:July 10th, 2026
CVSS Scoring

CVSS v3: 9.8 (CRITICAL)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Software
From NVD CPE configuration data

Vendors

joomlic

Products

icagenda
Weaknesses (CWE)

Source: NIST NVD · Data may lag official sources by up to one minute