CVE detail
CVE-2026-48939
A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 24.9 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 10.4
Why it matters now
Mention timeline
- Total mentions
- 5
- within the 30d window
- Peak daily
- 2
- highest bucket
Evidence
Source links by recency
11 source links · newest first
- Baddies caught exploiting extensions bugs with perfect 10 scores on vulnerable Joomla websitesThe Register Security
that can ultimately be executed as PHP code on the server, handing over remote control of the affected site. CISA added CVE-2026-48939, affecting iCagenda, and CVE-2026-56291, affecting Balbooa Forms, to its KEV catalog this week after confirming in-the-wild exploitation. Federal civilian agencies were ordered to patch against the flaws under the agenc
newswww.theregister.comJul 14, 2026, 11:06 AM la extensions that allow unauthenticated attackers to achieve remote code execution (RCE). The Balbooa flaw, tracked as CVE-2026-56291 (CVSS score of 10), is described as an unauthenticated arbitrary file upload issue affecting the extension’s frontend attachment upload endpoint. Balbooa Forms version 2.4.1 was released on July 9 with patches for the b
newswww.securityweek.comJul 13, 2026, 9:08 AMorts of zero-day exploitation in the wild. The vulnerabilities, both rated 10.0 on the CVSS scoring system, are below - CVE-2026-48939 - A vulnerability in the
newsthehackernews.comJul 13, 2026, 5:36 AM- U.S. CISA adds iCagenda and Balbooa Forms flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs
enda and Balbooa Forms flaws to its Known Exploited Vulnerabilities (KEV) catalog . The flaws added to the catalog are: CVE-2026-48939 (CVSS score of 10.0) iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability CVE-2026-56291 Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability iCagenda is an open-source event man
newssecurityaffairs.comJul 11, 2026, 7:31 PM wo new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-48939 iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability CVE-2026-56291 Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability These types of vulnerabilities are a frequent attack vect
governmentwww.cisa.govJul 10, 2026, 12:00 PM- https://www.icagenda.com/docs/changelog/icagenda-4-0-8www.icagenda.com
No excerpt available.
Release Noteswww.icagenda.comJun 20, 2026, 1:16 PM - https://www.icagenda.com/docs/changelog/icagenda-3-9-15www.icagenda.com
No excerpt available.
Release Noteswww.icagenda.comJun 20, 2026, 1:16 PM No excerpt available.
Mitigationwww.cisa.govJun 20, 2026, 1:16 PMNo excerpt available.
Exploitmysites.guruJun 20, 2026, 1:16 PMNo excerpt available.
Exploitgithub.comJun 20, 2026, 1:16 PM- https://www.icagenda.com/www.icagenda.com
No excerpt available.
Release Noteswww.icagenda.comJun 20, 2026, 1:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
2 repository references · best confidence 0.99 · max 2 stars
- shinthink/CVE-2026-48939High confidencegithubDiscovery source unavailable2 starsDiscovered Jul 9, 2026, 1:19 AM
- Polosss/By-Poloss..-..CVE-2026-48939High confidencegithubNVD Exploit reference0 starsDiscovered Jul 11, 2026, 6:10 AM
NVD labels the source link as Exploit; this is not independent verification of the repository's code.
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-13714CVSS 9.8 · Critical
The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.3.0 does not validate the type of uploaded files, and its file upload functionality is gated only by an…
- CVE-2026-10818CVSS 8.1 · High
The WPForms Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.10.1.1 via the ajax_chunk_upload_finalize function. This is due…
- CVE-2026-24727CVSS 9.3 · Critical
An unrestricted upload of file with dangerous type vulnerability in the e-paper draft upload function of SUNNET Corporate Training Management System through v10.3 allows remote au…
- CVE-2026-65461CVSS 9.1 · Critical
Administrator Arbitrary File Upload in Really Simple CSV Importer <= 1.3 versions.
- CVE-2026-65455CVSS 9.1 · Critical
Administrator Arbitrary File Upload in MapSVG <= 8.14.0 versions.
- CVE-2026-27064CVSS 9.1 · Critical
Editor Arbitrary File Upload in Mailster <= 4.1.17 versions.