SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-77990

MEDIUM · CVSS 5.3 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-08-27 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Joomla Event Manager extension prior to version 5.0.1 allows any logged-in user to access attendee lists, including names, usernames, registration dates, and statuses for events they do not manage, even for unpublished events. This vulnerability poses a risk of unauthorized information disclosure, which could lead to privacy concerns and potential misuse of attendee data. Joomla administrators and users of the affected extension should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-77990
Severity
MEDIUM
CVSS
5.3
EPSS
0.21%

Original NVD Description

Joomla Extension - joomlaeventmanager.net - Attendee lists readable by any logged-in user in Joomla Event Manager < 5.0.1 - A non-manager can therefore read attendee names, usernames, registration dates and statuses for events they do not manage, including lists belonging to unpublished events.