Legend: !important+added-removed~changed#fixed iCagenda™ is distributed under the terms of the GNU General Public License version 3 or later; see LICENSE.txt.
iCagenda 3.9.16 (2026.08.14) (Security Release)
!
Medium to Low-Medium security fixes and hardenings.
#
[SECURITY][CVE-2026-67366][MEDIUM] Fixed: CSRF on frontend registration actions.
#
[SECURITY][CVE-2026-71570][MEDIUM] Fixed: ACL bypass allowing arbitrary Joomla user enumeration (admin-only).
#
[SECURITY][CVE-2026-71571][MEDIUM] Fixed: SQL injection risk via unescaped numeric filter (admin-only).
~
[SECURITY] Hardening: Hardening output escaping for venue/city/country/address.