CVE-2026-48939
KEV Critical · CVSS 9.8iCagenda extension for Joomla — Arbitrary File Upload leading to Remote Code Execution (PHP code upload and execution)
- CVSS
- 9.8
- nvd
- EPSS
- —
- KEV
- Listed
- 2026-07-10
- Class
- other
- CWE-434, CWE-434
Description
A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.
Search profile — drives PoC discovery
Symbols iCagendafile attachmentcom_icagendauploadPHP file uploadarbitrary file uploadRCE
Keywords CVE-2026-48939iCagenda Joomla arbitrary file uploadiCagenda RCEiCagenda zero day file uploadiCagenda PHP upload exploitJoomla iCagenda attachment upload vulnerabilityiCagenda 3.9.15iCagenda 4.0.8com_icagenda file upload PoC
Versions: < 3.9.15 and < 4.0.8
Ranked PoCs (2) — best first
Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.
- ★ 0
- ★ 1
Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.
References
- https://www.icagenda.com/
- https://github.com/Polosss/By-Poloss..-..CVE-2026-48939
- https://mysites.guru/blog/icagenda-zero-day-file-upload-rce/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-48939
- https://www.icagenda.com/docs/changelog/icagenda-3-9-15
- https://www.icagenda.com/docs/changelog/icagenda-4-0-8
Status: enriched · ingested 2026-07-01T00:00:14.000Z · profiled 2026-07-01T18:30:14.000Z