cbcvebase.
CVE-2026-48939
published 2026-06-20

CVE-2026-48939: A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code…

PriorityP199critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2026-07-13
Exploited in the wild
EPSS
82.50%
99.6th percentile
A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.

Affected

3 ranges
VendorProductVersion rangeFixed in
icagenda.comicagenda_extension_for_joomla
joomlicicagenda>= 3.2.1 < 3.9.153.9.15
joomlicicagenda>= 4.0.0 < 4.0.84.0.8

Detection & IOCsextracted from sources · hover to see the quote

  • The vulnerability allows unrestricted file upload via the iCagenda extension's file attachment feature, enabling PHP code upload and execution. Monitor for PHP file uploads in Joomla iCagenda attachment directories.
  • Flag any uploaded files with PHP extensions (e.g., .php, .php5, .phtml, .phar) in Joomla iCagenda component upload/attachment paths as potential webshell drops.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.010.0CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:X/U:Red
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.