CVE-2026-48939
CRITICAL CISA KEVCVSS v3.1: 9.8 · EPSS: 0.0150 (71.4 percentile) · CISA KEV: Yes
Source data as of:
At a glance
- Severity
- CRITICAL
- CVSS
- 9.8 v3.1 · NVD
- EPSS
- 0.0150 (71.4 percentile) · FIRST.org
- CISA KEV
- Yes KEV added: 2026-07-10
- Type
- Unrestricted Upload · NVD CWE
- Attack conditions (CVSS vector)
- NetworkNo privilegesNo user interaction · Source: NVD Vector
- Affected vendors
- joomlic
- Published
- 2026-06-20 · Modified: 2026-07-11
- References
- Jump to references (6)
CVSS / EPSS / KEV
Source — CVSS: NVD · EPSS: FIRST.org · KEV: CISA. Data & Sources
Description
A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.
References
Reference URLs as listed by NVD, grouped by a mechanical match on the link's host/pattern. Labels describe the link type only.
- Reference https://www.icagenda.com/
- Reference https://github.com/Polosss/By-Poloss..-..CVE-2026-48939
- Reference https://mysites.guru/blog/icagenda-zero-day-file-upload-rce/
- CISA https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-48939
- Patch https://www.icagenda.com/docs/changelog/icagenda-3-9-15
- Patch https://www.icagenda.com/docs/changelog/icagenda-4-0-8