CVE-2026-48939
CRITICAL
CVSS: 9.8
EPSS: 20.1%
VulnCheck KEV
PoC Available
CWE-434
CWE-434
T1105
A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.
Published: 2026-06-20