PT-2026-60787 · Joomla · Events Booking

·

CVE-2026-60025

·

Published

2026-07-17

·

Updated

2026-07-20

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Events Booking versions prior to 5.8.0
Description The Joomla extension contains a frontend file upload endpoint that lacks Cross-Site Request Forgery (CSRF) protection. CSRF is a type of attack that tricks a victim into submitting a malicious request. This flaw allows an attacker to perform actions on behalf of an authenticated user without their consent.
Recommendations Update to version 5.8.0 or later.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-60025

Affected Products

Events Booking