SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-78071

HIGH · CVSS 7.5 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-08-28 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The DP Calendar extension for Joomla versions 7.0.0 to 10.11.2 is vulnerable to an authenticated, privileged stored cross-site scripting (XSS) attack due to improper escaping of location titles rendered in data attributes. This vulnerability allows attackers with create permissions in DPCalendar to inject malicious scripts, potentially compromising user sessions and data integrity. Joomla administrators and users of the affected DP Calendar extension should prioritize patching or mitigating this vulnerability to safeguard their applications.

CVE
CVE-2026-78071
Severity
HIGH
CVSS
7.5
EPSS
0.30%

Original NVD Description

Joomla Extension - digital-peak.com - Authenticated, privileged stored XSS in DP Calendar 7.0.0-8.19.5, 9.0.0-10.12.0 - Location title is rendered in data attribute without escaping leads to XSS, needs create permission in DPCalendar.