iCagenda
Coverage of iCagenda in the Nexus archive.
- Baddies caught exploiting extensions bugs with perfect 10 scores on vulnerable Joomla websites
CISA added two critical Joomla extension vulnerabilities (iCagenda and Balbooa Forms) to its KEV catalog, both rated with a CVSS score of 10. Attackers exploited these flaws to upload malicious PHP code, enabling remote server control. Patches are available, but exploitation continues on unpatched sites.
- CISA warns of actively exploited RCE flaws in Joomla extensions
CISA is warning about actively exploited remote code execution (RCE) vulnerabilities in the iCagenda and Balbooa Forms extensions for Joomla. Attackers are leveraging these flaws to achieve RCE through arbitrary file uploads.
- iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days
CISA added two maximum-severity vulnerabilities in iCagenda and Balbooa Joomla extensions to its KEV catalog, citing reports of zero-day exploitation. Both flaws, rated 10.0 on the CVSS scale, are being actively exploited.