iCagenda / ChangeLog

Keep Connected!

iCagenda 4.0.13 (Security Release)

Legend: !important +added -removed ~changed #fixed
iCagenda™ is distributed under the terms of the GNU General Public License version 3 or later; see LICENSE.txt.

  iCagenda 4.0.13 (2026.08.18) (Security & Bugfix Release)

  • !
    Critical Security and bugfix Release.
  • #
    [SECURITY][CRITICAL][4.0.8-4.0.12][CVE-2026-XXXXX] Fixed (regression introduced in 4.0.8)
  • When the submit form is public; Stored (persistent) XSS in the frontend event-submission form.
  • NOTE: By default, the "Submit an Event" form in frontend is set to registered. This vulnerability
  • is exploitable if the frontend form to submit an event is published and set to public access.
  • This vulnerability was responsibly reported by Akinlabi Omoogun of lulztigre.pw
  • I thank Akinlabi for reporting this issue and helping me improve the security of iCagenda.
  • ~
    Changed: Replace "text" type form fields (with a custom positive integer rule) with a "number" type field using the native Joomla rule.
  • #
    [LOW] Fixed: Events submitted in frontend not visible in admin list of events.
  • #
    [LOW][J6] Fixed: Date time format option broken in the Menu item option of type "List of Events".

 

Follow Us

Search