iCagenda / ChangeLog

Keep Connected!

iCagenda 4.0.12 (Security Release)

Legend: !important +added -removed ~changed #fixed
iCagenda™ is distributed under the terms of the GNU General Public License version 3 or later; see LICENSE.txt.

  iCagenda 4.0.12 (2026.08.14) (Security Release)

  • !
    Critical Security Release and Medium to Low-Medium security fixes and hardenings.
  • #
    [SECURITY][CVE-2026-67365][CRITICAL] Fixed: Unauthenticated SQL injection via mod_icagenda_calendar / com_ajax.
  • This vulnerability was responsibly reported by Joep van Antwerpen of Onvio.
  • I thank Joep for responsibly reporting this issue and helping me improve the security of iCagenda.
  • #
    [SECURITY][CVE-2026-67366][MEDIUM] Fixed: CSRF on frontend registration actions.
  • #
    [SECURITY][CVE-2026-71570][MEDIUM] Fixed: ACL bypass allowing arbitrary Joomla user enumeration (admin-only).
  • #
    [SECURITY][CVE-2026-71571][MEDIUM] Fixed: SQL injection risk via unescaped numeric filter (admin-only).
  • ~
    [SECURITY] Hardening: Hardening output escaping for venue/city/country/address.

 

Follow Us

Search