Executive brief
Joomla Event Manager is a free extension for Joomla websites that manages events, venues, calendars, and registrations. Versions before 5.0.1 contain a vulnerability in the administrator interface that allows privileged users (those with admin access) to upload dangerous file types including PHP scripts, leading to remote code execution on the web server.
Technical details
The vulnerability exists in the administrator source model component of Joomla Event Manager, which insufficiently validates file types during upload operations. An authenticated administrator can upload malicious PHP files or other dangerous file types that bypass file-type restrictions, resulting in arbitrary code execution on the server. The attack requires administrator privileges and access to the backend interface. This issue was addressed in version 5.0.1. The vulnerability class is improper file upload validation leading to remote code execution.
Affected products
- JoomlaEventManager.net Joomla Event Manager < 5.0.1
Timeline
- 2026-08-27: disclosed