PT-2026-82424 · Joomla · Joomla Events Manager

CVE-2026-77989

·

Published

2026-08-27

·

Updated

2026-08-27

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Joomla Events Manager versions prior to 5.0.1
Description A reflected Cross-Site Scripting (XSS) issue exists in the PDF export link. The buildCurrentPdfLink function copies the current request query string into the PDF button URL, which is then echoed unescaped by the pdfbutton() function, allowing for the execution of malicious scripts.
Recommendations Update Joomla Events Manager to version 5.0.1 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77989

Affected Products

Joomla Events Manager