Junglewise Threat Intelligence

CVE-2026-71571: JoomliC iCagenda authenticated SQL injection in numeric filter

CVE-2026-71571 · Severity: info · CVSS 0 · Published 2026-08-14

Technologies: JoomliC iCagenda.

Executive brief

iCagenda is a Joomla extension for managing events on websites. Authenticated backend operators with permission to access iCagenda can inject SQL code through an unescaped numeric filter, potentially allowing them to read or modify database contents without proper authorization.

Technical details

An authenticated SQL injection vulnerability exists in iCagenda versions below 2.0.0-4.0.11, stemming from insufficient input validation in a numeric filter parameter. The vulnerable component fails to properly escape user-supplied input in SQL queries accessible to backend operators with iCagenda permissions. An authenticated attacker with backend access can exploit this to inject arbitrary SQL commands, potentially exfiltrating sensitive data or modifying database records. The vulnerability requires prior authentication and appropriate backend permissions, limiting exposure to trusted users. A patch is available in version 2.0.0-4.0.11 and later.

Affected products

  • JoomliC iCagenda before 2.0.0-4.0.11

Timeline

  • 2026-08-14: disclosed

References