iCagenda 4.0.13 (Security Release) Stable
Release Notes 4.0.13
! Critical Security and bugfix Release.
# [SECURITY][CRITICAL][4.0.8-4.0.12][CVE-2026-XXXXX] Fixed (regression introduced in 4.0.8)
When the submit form is public; Stored (persistent) XSS in the frontend event-submission form.
NOTE: By default, the "Submit an Event" form in frontend is set to registered. This vulnerability is exploitable if the frontend form to submit an event is published and set to public access.
This vulnerability was responsibly reported by Akinlabi Omoogun of lulztigre.pw
I thank Akinlabi for reporting this issue and helping me improve the security of iCagenda.
~ Changed: Replace "text" type form fields (with a custom positive integer rule) with a "number" type field using the native Joomla rule.
# [LOW] Fixed: Events submitted in frontend not visible in admin list of events.
# [LOW][J6] Fixed: Date time format option broken in the Menu item option of type "List of Events".