On 15 June 2026 I released iCagenda 4.0.8 to fix the entry point allowing guests to create events on all versions of Joomla and a critical vulnerability on websites using Joomla 6 (6.0.0-6.1.1).
Versions affected: iCagenda 3.2.1 - 4.0.7
| Joomla version | Joomla 2.5 | Joomla 3 | Joomla 4 | Joomla 5 | Joomla 6 (prior to 6.1.2) |
|---|---|---|---|---|---|
| iCagenda version | 3.2.1-3.6.14 | 3.2.1-3.9.14 | 3.8.0-4.0.7 | 3.9.0-4.0.7 | 3.9.14-4.0.7 |
| Submit event vulnerability | yes | yes | yes | yes | yes |
| Critical upload vulnerability | no | no | no | no | yes |
Important Note (20 June 2026):
We have identified 2 vulnerabilities, both patched since iCagenda 4.0.8:
- An entry point allowing guests to create events, published but not approved, therefore not visible on the public interface of the site (on all versions of Joomla).
- A critical vulnerability allowing the upload of arbitrary files in the file attachment feature (on Joomla 6.0 to 6.1.1, other Joomla versions are not affected by this vulnerability).
Unsafe file uploads were already blocked by default on all Joomla versions prior to Joomla 6. Only install of iCagenda on Joomla 6 (6.0.0-6.1.1) had the critical upload vulnerability.
As of Joomla version 6.1.2, the default blocking mechanism has been reinstated in the framework for file uploads.If you don't have updated yet, please do!
If you haven't updated yet, please do so immediately. This vulnerability has been actively exploited since 15 June at 8 a.m. UTC, and the attacks are automated and target Joomla sites on which iCagenda is installed.
After updating to version 4.0.8 or higher, an alert message will appear if iCagenda detects a potential vulnerability in your iCagenda installation. Please read this message carefully. If you do not see this alert message after the update is complete, your system may not be compromised, but we cannot guarantee this.
The update closes the entry point and protect the file attachment feature, but does not clean up an already compromised site. If you were affected by this vulnerability before the update, it will not remove any elements that the attacker may have left behind and that we cannot monitor.
Keep a copy of any suspicious files as evidence, delete them, change your Joomla passwords and credentials, and audit your entire site, not just the iCagenda folder.
If you prefer not to perform this site integrity check manually, or if you manage multiple sites, mysites.guru offers a free audit that analyzes the entire site, including files located outside the public web root.
To allow everyone time to update before the details are made public, I will provide more information later.
Details are now public: CVE-2026-48939
If you don't have updated yet, please update right now!
The version 4.0.8 is for Joomla 4 up to latest Joomla 6 version.
On 16 June 2026, I released version 3.9.15 to fix the security of event submission in guest access, on Joomla 3 websites.
Note: iCagenda 4.x does not support Joomla 3, and iCagenda 3.9 (Joomla 3.10) will only receive security patches until 13 October 2026.
If you have any questions please post on the forum or open a new support ticket if you own an active Pro Subscription.