cbcvebase.

Joomlaeventmanager.Net Jem Joomla Event Manager Extension For Joomla vulnerabilities

5 known vulnerabilities affecting joomlaeventmanager.net/jem_joomla_event_manager_extension_for_joomla.

Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1MEDIUM4

Vulnerabilities

Page 1 of 1
CVE-2026-77991P2CRITICALCVSS 9.4v1.0.0-5.0.02026-08-27
CVE-2026-77991 [CRITICAL] CWE-434 CVE-2026-77991: Joomla Extension - joomlaeventmanager.net - Privileged remote code execution in Joomla Event Manager Joomla Extension - joomlaeventmanager.net - Privileged remote code execution in Joomla Event Manager < 5.0.1 - The administrator source model allows to write dangerous file type incl. PHP, leading to remote code execution.
nvd
CVE-2026-77034P3MEDIUMCVSS 6.9v1.0.0-5.0.02026-08-27
CVE-2026-77034 [MEDIUM] CWE-284 CVE-2026-77034: Joomla Extension - joomlaeventmanager.net - Unauthenticated article overwrite and force-publish in J Joomla Extension - joomlaeventmanager.net - Unauthenticated article overwrite and force-publish in Joomla Event Manager < 5.0.1 - Any visitor holding their own session token can republish and overwrite an article associated with an event.
nvd
CVE-2026-77990P4MEDIUMCVSS 5.3v1.0.0-5.0.02026-08-27
CVE-2026-77990 [MEDIUM] CWE-639 CVE-2026-77990: Joomla Extension - joomlaeventmanager.net - Attendee lists readable by any logged-in user in Joomla Joomla Extension - joomlaeventmanager.net - Attendee lists readable by any logged-in user in Joomla Event Manager < 5.0.1 - A non-manager can therefore read attendee names, usernames, registration dates and statuses for events they do not manage, including lists belonging to unpublished events.
nvd
CVE-2026-77989P4MEDIUMCVSS 5.3v1.0.0-5.0.02026-08-27
CVE-2026-77989 [MEDIUM] CWE-79 CVE-2026-77989: Joomla Extension - joomlaeventmanager.net - Reflected XSS via the PDF export link in Joomla Events M Joomla Extension - joomlaeventmanager.net - Reflected XSS via the PDF export link in Joomla Events Manager < 5.0.1 - buildCurrentPdfLink copies the current request query string into the PDF button URL, and pdfbutton() echoes it unescaped, leading to an reflected XSS vector.
nvd
CVE-2026-77035P4MEDIUMCVSS 5.1v1.0.0-5.0.02026-08-27
CVE-2026-77035 [MEDIUM] CWE-639 CVE-2026-77035: Joomla Extension - joomlaeventmanager.net - Cross-user event and venue takeover through forged form Joomla Extension - joomlaeventmanager.net - Cross-user event and venue takeover through forged form fields in Joomla Event Manager < 5.0.1 - A registered user with edit-own rights (the eventowner=1 setting or core.edit.own) can POST another user's record id together with their own id as created_by and take over that record.
nvd
Joomlaeventmanager.Net Jem Joomla Event Manager Extension For Joomla vulnerabilities | cvebase