CVE-2026-67366

Erweiterung für Joomla - icagenda.

mediumEPSS 0.2%

Description

Joomla Extension - icagenda.com - CSRF on frontend registration actions in iCagenda < 2.0.0-4.0.11 - Multiple state changing operations in the frontend are callable without a CSRF token check.

Metrics

5.3
Source: cna-v4
10.8 %
Elevated — this CVE ranks above at least 10% of all CVEs scored today.
Show all metrics
Severity
medium
no public PoC known
0.2 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-08-14 20:08 UTC
CWE-352

Weakness classes (CWE)

  • CWE-352Compound

    Cross-Site Request Forgery (CSRF)

    The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

    cwe.mitre.org →

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Modified2026-08-17 16:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-67366","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…