Skip to main content

This summer, I conducted an in-depth analysis and audit of the iCagenda extension, which included reducing entry points, strengthening input validation, and fixing an Ajax-based SQL injection vulnerability in the calendar module—following an external report by Joep van Antwerpen (Onvio) on 13 August 2026, which was confirmed by the developer (yours truly) on 14 August.

On 14 August 2026 I released iCagenda 4.0.12 to fix those multiple security issues, from low-medium to critical.

The Ajax-based SQL injection vulnerability (issue #0) was responsibly reported by Joep van Antwerpen (Onvio). 
I thank Joep for responsibly reporting this issue and helping me improve the security of iCagenda.

All users running an affected version should update immediately.

 

Security Advisory 

Issue #0: Unauthenticated SQL injection
Security Level: Critical
CVE
: CVE-2026-67365
Versions affected
: Versions 4.0.0 through 4.0.11 are affected.

Joomla version Joomla 3 Joomla 4 Joomla 5 Joomla 6
iCagenda versions affected none 4.0.0-4.0.11 4.0.0-4.0.11 4.0.0-4.0.11
Unauthenticated SQL injection via mod_icagenda_calendar / com_ajax no yes yes yes

 

Issue #1: CSRF
Security Level: Medium
CVE
: CVE-2026-67366
Versions affected
: Versions 2.0.0 through 4.0.11 are affected.

Joomla version Joomla 3 Joomla 4 Joomla 5 Joomla 6
iCagenda versions affected 2.0.0-3.9.15 3.8.0-4.0.11 3.9.0-4.0.11 4.0.0-4.0.11
CSRF on frontend registration actions yes yes yes yes

 

Issue #2: ACL bypass (admin only)
Security Level: Medium
CVE
: CVE-2026-71570
Versions affected
: Versions 3.6.0 through 4.0.11 are affected.

Joomla version Joomla 3 Joomla 4 Joomla 5 Joomla 6
iCagenda versions affected 3.6.0-3.9.15 3.8.0-4.0.11 3.9.0-4.0.11 4.0.0-4.0.11
ACL bypass allowing arbitrary Joomla user enumeration yes yes yes yes

 

Issue #3: SQL injection (admin only)
Security Level: Medium
CVE
: CVE-2026-71571
Versions affected
: Versions 3.0.0 through 4.0.11 are affected.

Joomla version Joomla 3 Joomla 4 Joomla 5 Joomla 6
iCagenda versions affected 3.0.0-3.9.15 3.8.0-4.0.11 3.9.0-4.0.11 4.0.0-4.0.11
CSRF on frontend registration actions yes yes yes yes

 

If you don't have updated yet, please update right now!

The version 4.0.12 is for Joomla 4 up to latest Joomla 6 version.

On 14 August 2026, I released version 3.9.16 to fix the security issues #1 to #3, on Joomla 3 websites. iCagenda versions for Joomla 3 are not affected by the critical security issue in the new iCagenda 4 Calendar module.
Note: iCagenda 4.x does not support Joomla 3, and iCagenda 3.9 (Joomla 3.10) will only receive security patches until 13 October 2026.

If you have any questions please post on the forum or open a new support ticket if you own an active Pro Subscription.

 

Lastest Reviews

Cool extension, great support        

Cool way to publish events, and is good for various scenarios, calendar and event views are efficient.

Excellent module et support nickel         

Excellent composant pour une asso qui doit gérer des événements avec inscriptions limitées aux membres.

Maximum satisfaction with the component        

I have been very satisfied with the tool for several years, using it for example to promote hundreds of events of a large cultural center, a community center for foreigners and others. Website visitors appreciate clarity, filterability, but also generating the history of events.

Alles Super        

Anzeigen von Events im Bundesland Bayern in Deutschland. Alle Events sind super leicht erklärt und es gibt sehr hohen Response.

Love what we do?

     
Spread the word!

Let us know by leaving a review on the JED and boost our motivation!   

Write a Review