Joomla Extension - icagenda.com - Authenticated SQL injection via unescaped numeric filter in iCagenda < 2.0.0-4.0.11 - Backend operators with permissions to access iCagenda could inject SQL.
We have discovered 446 live websites that are affected by CVE-2026-71571.
| Product | |
| Category | Event Management |
| Vulnerable Domains | 446 live websites (40% of iCagenda install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 10 versions ( 12% of all versions) |
| 17 websites | |
| 161 websites | |
| 71 websites | |
| 46 websites | |
| 45 websites | |
| 16 websites | |
| 14 websites | |
| 12 websites | |
| 8 websites | |
| 8 websites |
| .de | 132 websites |
| .fr | 46 websites |
| .ch | 43 websites |
| .nl | 43 websites |
| .com | 43 websites |
| .org | 29 websites |
| .at | 13 websites |
| .pl | 10 websites |
| .it | 9 websites |
| .eu | 8 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ***********.org | ***,*** | ||
| ***.***.cz | ***,*** | ||
| ********.edu | ***,*** | ||
| *******************.org | ***,*** | ||
| ****************.org | ***,*** | ||
| ***.no | *,***,*** | ||
| ******.cz | *,***,*** | ||
| ********.de | *,***,*** | ||
| *****************.org | *,***,*** | ||
| *************.de | *,***,*** |
FAQ