PT-2026-72114 · Icagenda · Icagenda

CVE-2026-67365

·

Published

2026-08-14

·

Updated

2026-08-17

CVSS v4.0

9.2

Critical

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:L/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions iCagenda versions prior to 4.0.11
Description An unauthenticated SQL injection exists in the mod icagenda calendar module. This issue is reachable via the com ajax endpoint without requiring a session, token, or account. SQL injection is a technique where an attacker inserts malicious SQL code into a query, potentially allowing unauthorized access to or manipulation of the database.
Recommendations Update iCagenda to version 4.0.11 or later.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67365

Affected Products

Icagenda