iCagenda iCagenda Vulnerability
iCagenda contains an unrestricted upload of file with dangerous type vulnerability that allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.
CVSS Score
9.8
CRITICAL
Published
10 Jul 2026 00:00
Modified
N/A
Vendor
iCagenda
Product
iCagenda
Source
CIRCL
Affected Versions
Fix
Vendor Patch / Mitigation Available
Weaknesses (CWE)
CWE-434
Affected Systems
iCagenda
iCagenda
ICagenda
ICagenda
External Links
KEV Status
Known Exploited Vulnerability