Executive brief
DP Calendar is a popular event management and calendar extension for the Joomla content management system. A security vulnerability allows unauthenticated attackers to perform SQL injection attacks, which could lead to the unauthorized exposure of sensitive database information. This poses a significant risk to data confidentiality and the overall security of websites using the affected versions of the extension.
Technical details
A SQL injection vulnerability (CWE-89) exists in the DP Calendar extension for Joomla, affecting versions 8.18.0 through 10.11.1. The flaw allows an unauthenticated remote attacker to send specially crafted requests to the application to execute arbitrary SQL commands. According to the CVSS 4.0 vector, the primary impact is on data confidentiality (VC:H), suggesting that an attacker can extract sensitive information from the database without requiring any user interaction or prior authentication. Users should update to a patched version provided by Digital Peak.
Affected products
- digital-peak.com DP Calendar extension for Joomla 8.18.0-10.11.1
Timeline
- 2026-07-15: advisory: CVE published by the Joomla! Project