A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.
References
| Link | Resource |
|---|---|
| https://www.icagenda.com/ | Product |
| https://github.com/Polosss/By-Poloss..-..CVE-2026-48939 | Exploit Third Party Advisory |
| https://mysites.guru/blog/icagenda-zero-day-file-upload-rce/ | Third Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-48939 | US Government Resource |
| https://www.icagenda.com/docs/changelog/icagenda-3-9-15 | Release Notes |
| https://www.icagenda.com/docs/changelog/icagenda-4-0-8 | Release Notes |
Configurations
Configuration 1 (hide)
|
History
10 Jul 2026, 19:12
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/Polosss/By-Poloss..-..CVE-2026-48939 - Exploit, Third Party Advisory | |
| References | () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-48939 - US Government Resource |
10 Jul 2026, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
05 Jul 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE |
02 Jul 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
30 Jun 2026, 18:37
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:joomlic:icagenda:*:*:*:*:-:joomla\!:*:* | |
| References | () https://www.icagenda.com/ - Product | |
| References | () https://mysites.guru/blog/icagenda-zero-day-file-upload-rce/ - Third Party Advisory | |
| References | () https://www.icagenda.com/docs/changelog/icagenda-3-9-15 - Release Notes | |
| References | () https://www.icagenda.com/docs/changelog/icagenda-4-0-8 - Release Notes | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
| First Time |
Joomlic icagenda
Joomlic |
|
| CWE | CWE-434 |
24 Jun 2026, 19:17
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
20 Jun 2026, 13:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-20 13:16
Updated : 2026-07-11 05:16
NVD link : CVE-2026-48939
Mitre link : CVE-2026-48939
CVE.ORG link : CVE-2026-48939
JSON object : View
Products Affected
joomlic
- icagenda
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type
