CVE-2026-67366

Joomla Extension - icagenda.com - CSRF on frontend registration actions in iCagenda < 2.0.0-4.0.11

Joomla Extension - icagenda.com - CSRF on frontend registration actions in iCagenda < 2.0.0-4.0.11 - Multiple state changing operations in the frontend are callable without a CSRF token check.


We have discovered 1,130 live websites that are affected by CVE-2026-67366.

Run a Free Instant Scan




Affected Software

Product  iCagenda
Category Event Management
Vulnerable Domains1,130 live websites (100% of iCagenda install base)
Vulnerable Versions
  • from 2 through 4.0.12
Vulnerable Versions Count81 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-352 Cross-Site Request Forgery (CSRF)



Details

  • Published - Aug 14, 2026
  • Updated - Aug 18, 2026

Website Distribution by Country

Number of websites using CVE-2026-67366
United States60 websites



Germany304 websites
France202 websites
Italy112 websites
Switzerland82 websites
Netherlands76 websites
Poland37 websites
Austria28 websites
Czech Republic22 websites
Belgium21 websites

Website Distribution by TLD

Number of websites using CVE-2026-67366
.de254 websites
.com139 websites
.fr129 websites
.ch79 websites
.it73 websites
.nl72 websites
.org70 websites
.at30 websites
.pl27 websites
.net21 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-67366

Top websites that are affected by CVE-2026-67366. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***********.org Italy***,***
***.***.cz Czech Republic***,***
******************.nl Netherlands***,***
*****.org Switzerland***,***
**************.com France***,***
*************.**.uk United States***,***
********.fr France***,***
********.edu United States***,***
*******************.org France***,***
*************.de Germany***,***
See full domain list

FAQ

CVE-2026-67366 is Cross-Site Request Forgery (CSRF) in iCagenda
A total of 1,130 websites have been identified as vulnerable to CVE-2026-67366, based on global website indexing conducted by WebTechSurvey.
The iCagenda is affected by the CVE-2026-67366 vulnerability.
iCagenda versions up to 4.0.12 are vulnerable to CVE-2026-67366.
CVE-2026-67366 is resolved in version 4.0.12 of iCagenda.