This summer, I conducted an in-depth analysis and audit of the iCagenda extension, which included reducing entry points, strengthening input validation, and fixing an Ajax-based SQL injection vulnerability in the calendar module—following an external report by Joep van Antwerpen (Onvio) on 13 August 2026, which was confirmed by the developer (yours truly) on 14 August.
On 14 August 2026 I released iCagenda 4.0.12 to fix those multiple security issues, from low-medium to critical.
The Ajax-based SQL injection vulnerability (issue #0) was responsibly reported by Joep van Antwerpen (Onvio).
I thank Joep for responsibly reporting this issue and helping me improve the security of iCagenda.
All users running an affected version should update immediately.
Security Advisory
Issue #0: Unauthenticated SQL injection
Security Level: Critical
CVE: CVE-2026-67365
Versions affected: Versions 4.0.0 through 4.0.11 are affected.
| Joomla version | Joomla 3 | Joomla 4 | Joomla 5 | Joomla 6 |
|---|---|---|---|---|
| iCagenda versions affected | none | 4.0.0-4.0.11 | 4.0.0-4.0.11 | 4.0.0-4.0.11 |
| Unauthenticated SQL injection via mod_icagenda_calendar / com_ajax | no | yes | yes | yes |
Issue #1: CSRF
Security Level: Medium
CVE: CVE-2026-67366
Versions affected: Versions 2.0.0 through 4.0.11 are affected.
| Joomla version | Joomla 3 | Joomla 4 | Joomla 5 | Joomla 6 |
|---|---|---|---|---|
| iCagenda versions affected | 2.0.0-3.9.15 | 3.8.0-4.0.11 | 3.9.0-4.0.11 | 4.0.0-4.0.11 |
| CSRF on frontend registration actions | yes | yes | yes | yes |
Issue #2: ACL bypass (admin only)
Security Level: Medium
CVE: CVE-2026-71570
Versions affected: Versions 3.6.0 through 4.0.11 are affected.
| Joomla version | Joomla 3 | Joomla 4 | Joomla 5 | Joomla 6 |
|---|---|---|---|---|
| iCagenda versions affected | 3.6.0-3.9.15 | 3.8.0-4.0.11 | 3.9.0-4.0.11 | 4.0.0-4.0.11 |
| ACL bypass allowing arbitrary Joomla user enumeration | yes | yes | yes | yes |
Issue #3: SQL injection (admin only)
Security Level: Medium
CVE: CVE-2026-71571
Versions affected: Versions 3.0.0 through 4.0.11 are affected.
| Joomla version | Joomla 3 | Joomla 4 | Joomla 5 | Joomla 6 |
|---|---|---|---|---|
| iCagenda versions affected | 3.0.0-3.9.15 | 3.8.0-4.0.11 | 3.9.0-4.0.11 | 4.0.0-4.0.11 |
| CSRF on frontend registration actions | yes | yes | yes | yes |
If you don't have updated yet, please update right now!
The version 4.0.12 is for Joomla 4 up to latest Joomla 6 version.
On 14 August 2026, I released version 3.9.16 to fix the security issues #1 to #3, on Joomla 3 websites. iCagenda versions for Joomla 3 are not affected by the critical security issue in the new iCagenda 4 Calendar module.
Note: iCagenda 4.x does not support Joomla 3, and iCagenda 3.9 (Joomla 3.10) will only receive security patches until 13 October 2026.
If you have any questions please post on the forum or open a new support ticket if you own an active Pro Subscription.