PT-2026-82424 · Joomla · Joomla Events Manager
CVE-2026-77989
·
Published
2026-08-27
·
Updated
2026-08-27
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Joomla Events Manager versions prior to 5.0.1
Description
A reflected Cross-Site Scripting (XSS) issue exists in the PDF export link. The
buildCurrentPdfLink function copies the current request query string into the PDF button URL, which is then echoed unescaped by the pdfbutton() function, allowing for the execution of malicious scripts.Recommendations
Update Joomla Events Manager to version 5.0.1 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Joomla Events Manager