CVE-2026-75948

Joomla Extension - icagenda.com - Authenticated Stored XSS in iCagenda 4.0.8 to 4.0.12

Joomla Extension - icagenda.com - Authenticated Stored XSS in iCagenda 4.0.8 to 4.0.12 - The frontend "Submit an Event" form stores the `image` and `file` fields as raw strings with no output-side HTML-attribute escaping.


We have discovered 320 live websites that are affected by CVE-2026-75948.

Run a Free Instant Scan




Affected Software

Product  iCagenda
Category Event Management
Vulnerable Domains320 live websites (29% of iCagenda install base)
Vulnerable Versions
  • from 4.0.8 through 4.0.13
Vulnerable Versions Count4 versions ( 4.94% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Aug 20, 2026
  • Updated - Aug 21, 2026

Credits

  • Akinlabi Omoogun of lulztigre.pw (finder)

Website Distribution by Country

Number of websites using CVE-2026-75948
United States11 websites



Germany116 websites
France53 websites
Netherlands35 websites
Switzerland29 websites
Italy11 websites
Poland11 websites
Austria10 websites
Belgium7 websites
GB6 websites

Website Distribution by TLD

Number of websites using CVE-2026-75948
.de95 websites
.nl34 websites
.fr34 websites
.com33 websites
.ch26 websites
.org23 websites
.at10 websites
.pl8 websites
.it6 websites
.eu6 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-75948

Top websites that are affected by CVE-2026-75948. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***********.org Italy***,***
***.***.cz Czech Republic***,***
********.edu United States***,***
*******************.org France***,***
****************.org France***,***
***.no Norway*,***,***
********.de Germany*,***,***
*****************.org GB*,***,***
*************.de Germany*,***,***
*******.fr France*,***,***
See full domain list

FAQ

CVE-2026-75948 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in iCagenda
A total of 320 websites have been identified as vulnerable to CVE-2026-75948, based on global website indexing conducted by WebTechSurvey.
The iCagenda is affected by the CVE-2026-75948 vulnerability.
iCagenda versions up to 4.0.13 are vulnerable to CVE-2026-75948.
CVE-2026-75948 is resolved in version 4.0.13 of iCagenda.