iCagenda 3.9.16 (Security Release Joomla 3.10) Stable
Release Notes 3.9.16
! Medium to Low-Medium security fixes and hardenings.
# [SECURITY][CVE-2026-67366][MEDIUM] Fixed: CSRF on frontend registration actions.
# [SECURITY][CVE-2026-71570][MEDIUM] Fixed: ACL bypass allowing arbitrary Joomla user enumeration (admin-only).
# [SECURITY][CVE-2026-71571][MEDIUM] Fixed: SQL injection risk via unescaped numeric filter (admin-only).
~ [SECURITY] Hardening: Hardening output escaping for venue/city/country/address.