- Details
The "Summer of Security" continues.
Joomla! just released today Joomla 6.1.3 and Joomla 5.4.8. These are security & bugfix releases for the Joomla 5.x and 6.x series.
And i released today iCagenda 4.0.13, a new Security & bugfix release for iCagenda versions 4.0.8 to 4.0.12.
This security vulnerability does not concern versions prior to 4.0.8. It's a regression introduced in version 4.0.8.
- Details
This summer, I conducted an in-depth analysis and audit of the iCagenda extension, which included reducing entry points, strengthening input validation, and fixing an Ajax-based SQL injection vulnerability in the calendar module—following an external report by Joep van Antwerpen (Onvio) on 13 August 2026, which was confirmed by the developer (yours truly) on 14 August.
On 14 August 2026 I released iCagenda 4.0.12 to fix those multiple security issues, from low-medium to critical. On the same day, I released version 3.9.16 to fix vulnerabilities in iCagenda installations on Joomla 3 sites.
- Details
On 15 June 2026 I released iCagenda 4.0.8 to fix the entry point allowing guests to create events on all versions of Joomla and a critical vulnerability on websites using Joomla 6 (6.0.0-6.1.1).