EUVD-2026-38109
A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.
- EUVD state
- Present in the current official mapping
- Known exploitation
- Recorded by ENISA since 10 Jul 2026. Evidence sources: cisa_kev.
- ENISA score
- 10.0 · CVSS 4.0
- Advisory evidence
- No linked advisory details stored yet
