ESC
Type to search CVEs in real-time
Enter open Esc close Ctrl K toggle

CVE-2026-48939

CRITICAL Export PDF

iCagenda iCagenda Vulnerability

iCagenda contains an unrestricted upload of file with dangerous type vulnerability that allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.

CVSS Score
9.8
CRITICAL
Published
10 Jul 2026 00:00
Modified
N/A
Vendor
iCagenda
Product
iCagenda
Source
CIRCL

Affected Versions

Fix Vendor Patch / Mitigation Available

Weaknesses (CWE)

CWE-434

Affected Systems

iCagenda
iCagenda
ICagenda
ICagenda

KEV Status

Known Exploited Vulnerability