18 Aoû
2026
Publication : 18 août 2026
Catégorie : ChangeLog
Legend: ! important + added - removed ~ changed # fixed iCagenda™ is distributed under the terms of the GNU General Public License version 3 or later; see LICENSE.txt.
iCagenda 4.0.13 (2026.08.18) (Security & Bugfix Release)
!
Critical Security and bugfix Release.
#
[SECURITY][CRITICAL][4.0.8-4.0.12][CVE-2026-XXXXX] Fixed (regression introduced in 4.0.8)
When the submit form is public; Stored (persistent) XSS in the frontend event-submission form.
NOTE: By default, the "Submit an Event" form in frontend is set to registered. This vulnerability
is exploitable if the frontend form to submit an event is published and set to public access.
This vulnerability was responsibly reported by Akinlabi Omoogun of lulztigre.pw
I thank Akinlabi for reporting this issue and helping me improve the security of iCagenda.
~
Changed: Replace "text" type form fields (with a custom positive integer rule) with a "number" type field using the native Joomla rule.
#
[LOW] Fixed: Events submitted in frontend not visible in admin list of events.
#
[LOW][J6] Fixed: Date time format option broken in the Menu item option of type "List of Events".