Executive brief
Joomla Events Manager is a free Joomla extension that helps organizations create and manage events, venues, calendars, and registrations on their websites. A reflected cross-site scripting (XSS) vulnerability in the PDF export feature allows attackers to inject malicious scripts into event pages through a crafted link, potentially capturing user credentials or performing unauthorized actions on behalf of visitors.
Technical details
This reflected XSS vulnerability exists in the buildCurrentPdfLink function, which copies the current request query string into the PDF button URL without proper sanitization. The pdfbutton() function then echoes this unescaped data directly into the page, allowing attackers to inject arbitrary JavaScript. The vulnerability affects Joomla Events Manager versions prior to 5.0.1 and requires no authentication—an attacker simply needs to craft a malicious URL with XSS payload in the query string and trick a user into clicking it. The attack vector is network-based and does not require user interaction beyond clicking a link. The vulnerability has been fixed in version 5.0.1 and later.
Affected products
- Joomla Events Manager Events Manager < 5.0.1
Timeline
- 2026-08-27: disclosed
- 2026-09-14: patched: Fixed in version 5.0.1 released 14 September 2026