Legend: !important+added-removed~changed#fixed iCagenda™ is distributed under the terms of the GNU General Public License version 3 or later; see LICENSE.txt.
iCagenda 4.0.12 (2026.08.14) (Security Release)
!
Critical Security Release and Medium to Low-Medium security fixes and hardenings.
#
[SECURITY][CVE-2026-67365][CRITICAL] Fixed: Unauthenticated SQL injection via mod_icagenda_calendar / com_ajax.
This vulnerability was responsibly reported by Joep van Antwerpen of Onvio.
I thank Joep for responsibly reporting this issue and helping me improve the security of iCagenda.
#
[SECURITY][CVE-2026-67366][MEDIUM] Fixed: CSRF on frontend registration actions.
#
[SECURITY][CVE-2026-71570][MEDIUM] Fixed: ACL bypass allowing arbitrary Joomla user enumeration (admin-only).
#
[SECURITY][CVE-2026-71571][MEDIUM] Fixed: SQL injection risk via unescaped numeric filter (admin-only).
~
[SECURITY] Hardening: Hardening output escaping for venue/city/country/address.