CVE-2026-48939

A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:joomlic:icagenda:*:*:*:*:-:joomla\!:*:*
cpe:2.3:a:joomlic:icagenda:*:*:*:*:-:joomla\!:*:*

History

10 Jul 2026, 19:12

Type Values Removed Values Added
References () https://github.com/Polosss/By-Poloss..-..CVE-2026-48939 - () https://github.com/Polosss/By-Poloss..-..CVE-2026-48939 - Exploit, Third Party Advisory
References () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-48939 - () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-48939 - US Government Resource

10 Jul 2026, 18:16

Type Values Removed Values Added
References
  • () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-48939 -

05 Jul 2026, 15:16

Type Values Removed Values Added
CWE CWE-284

02 Jul 2026, 17:16

Type Values Removed Values Added
References
  • () https://github.com/Polosss/By-Poloss..-..CVE-2026-48939 -

30 Jun 2026, 18:37

Type Values Removed Values Added
CPE cpe:2.3:a:joomlic:icagenda:*:*:*:*:-:joomla\!:*:*
References () https://www.icagenda.com/ - () https://www.icagenda.com/ - Product
References () https://mysites.guru/blog/icagenda-zero-day-file-upload-rce/ - () https://mysites.guru/blog/icagenda-zero-day-file-upload-rce/ - Third Party Advisory
References () https://www.icagenda.com/docs/changelog/icagenda-3-9-15 - () https://www.icagenda.com/docs/changelog/icagenda-3-9-15 - Release Notes
References () https://www.icagenda.com/docs/changelog/icagenda-4-0-8 - () https://www.icagenda.com/docs/changelog/icagenda-4-0-8 - Release Notes
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
First Time Joomlic icagenda
Joomlic
CWE CWE-434

24 Jun 2026, 19:17

Type Values Removed Values Added
References
  • () https://mysites.guru/blog/icagenda-zero-day-file-upload-rce/ -
  • () https://www.icagenda.com/docs/changelog/icagenda-3-9-15 -
  • () https://www.icagenda.com/docs/changelog/icagenda-4-0-8 -

20 Jun 2026, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-20 13:16

Updated : 2026-07-11 05:16


NVD link : CVE-2026-48939

Mitre link : CVE-2026-48939

CVE.ORG link : CVE-2026-48939


JSON object : View

Products Affected

joomlic

  • icagenda
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type