{"id":"CVE-2026-48939","title":"A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.","summary":"A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-284","CWE-434"],"vendor":"joomlic","product":"icagenda","affected":["icagenda >= 3.2.1, < 3.9.15","icagenda >= 4.0.0, < 4.0.8"],"patched":["icagenda 4.0.8"],"published":"2026-06-20","updated":"2026-07-03","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-48939","references":[{"url":"https://www.icagenda.com/","label":"security@joomla.org"},{"url":"https://github.com/Polosss/By-Poloss..-..CVE-2026-48939","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://mysites.guru/blog/icagenda-zero-day-file-upload-rce/","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://www.icagenda.com/docs/changelog/icagenda-3-9-15","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://www.icagenda.com/docs/changelog/icagenda-4-0-8","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","kev","in-the-wild","exploit-available"],"epss":0.20069,"epssPercentile":0.97379,"ingestedAt":"2026-07-03T13:02:27.809Z","kev":true,"exploited":true,"kevDateAdded":"2026-07-10","kevDueDate":"2026-07-13","kevRansomware":false,"exploits":{"github":3,"githubRepos":["https://github.com/shinthink/CVE-2026-48939","https://github.com/Polosss/By-Poloss..-..CVE-2026-48939","https://github.com/ChiefYoru/CVE-2026-48939_PoC"],"nuclei":["CVE-2026-48939"],"checkedAt":"2026-09-21T15:29:15.706Z"},"exploitAvailable":true,"slug":"CVE-2026-48939","body":"## Overview\n\nA vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.\n\n## Affected\n\n- `icagenda >= 3.2.1, < 3.9.15`\n- `icagenda >= 4.0.0, < 4.0.8`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `icagenda 4.0.8`","depth":"hadal","depthScore":83,"depthScoreParts":{"impact":53.9,"likelihood":4,"exploitation":25,"ransomware":0},"changes":[{"seq":5275,"id":"CVE-2026-48939","ts":1788887259559,"field":"exploit_available","old":"false","new":"true"},{"seq":4158,"id":"CVE-2026-48939","ts":1788886376356,"field":"exploit_available","old":"true","new":"false"},{"seq":2925,"id":"CVE-2026-48939","ts":1788883041737,"field":"exploit_available","old":"false","new":"true"},{"seq":1954,"id":"CVE-2026-48939","ts":1788882445020,"field":"exploit_available","old":"true","new":"false"},{"seq":1042,"id":"CVE-2026-48939","ts":1788881880905,"field":"exploit_available","old":"false","new":"true"},{"seq":176,"id":"CVE-2026-48939","ts":1787603643296,"field":"epss","old":"0.82501","new":"0.19727"},{"seq":121,"id":"CVE-2026-48939","ts":1786131729102,"field":"epss","old":"0.24347","new":"0.82501"},{"seq":91,"id":"CVE-2026-48939","ts":1784920485382,"field":"epss","old":"0.01505","new":"0.24347"},{"seq":64,"id":"CVE-2026-48939","ts":1783709604660,"field":"exploited","old":"false","new":"true"},{"seq":63,"id":"CVE-2026-48939","ts":1783709604660,"field":"kev","old":"false","new":"true"}]}