Main menu

Forum


The developer takes a few days off for Summer vacation...
...and will be back with charged battery!

From 1st August to 10th August, 2026 included
During this period,
assistance from developer will not be provided.

NEWS: iCagenda 4.1.0-alpha1 will be available for testing for users with a PRO subscription
by the end of August!

× Help Forum English

CVE-2026-48939

  • Sinna
  • Autore della discussione
  • New Member
  • New Member
Di più
3 Settimane 5 giorni fa #19091 da Sinna
CVE-2026-48939 è stato creato da Sinna
After reading  CISA Adds Two Known Exploited Vulnerabilities to Catalog , I wanted to upgrade an ancient version if iCagenda (3.6.6 Pro) to iCagenda 3.9.15. I however only can find the free version, but upgrading the current pro version to a free version results in an 0 - Call to a member function get() on bool crash taking the whole website down. This behavior is described in forum.joomlic.com/icagenda-help-en/3645-...event-list-mod#15064
Based on /administrator/index.php?option=com_icagenda&view=liveupdate, 3.6.6 is the latest version. I've checked the Update Sites URL for JoomliC PRO Update Server - pro.joomlic.com/icupdate/modules/updates.xml, but that URL is automatically redirected to www.joomlic.com/.

I do realize that running iCagenda 3.6.6 Pro on a Joomla! 3.10.12-website is no longer considered safe, but waiting for a new website, I should be able to keep this one up-and-running.

So my question is: is there an upgrade path from 3.6.6 Pro to 3.9.15 Pro available?
If not, how can I safely upgrade to 3.9.15 free without facing the 0 - Call to a member function get() on bool bug?

Thanks in advance,
Kris

Computer[h|z]ero

Si prega Accedi o Crea un account a partecipare alla conversazione.

  • Lyr!C
  • Avatar di Lyr!C
  • Administrator
  • Administrator
  • Lead Developer
Di più
3 Settimane 5 giorni fa - 3 Settimane 2 giorni fa #19092 da Lyr!C
Risposta da Lyr!C al topic CVE-2026-48939
Hello Kris,

First, your iCagenda installation on your Joomla 3 is "safe": it has no critical security issue (but your Joomla 3 installation is maybe not so safe as end of life...).

Only Joomla 6 from 6.0.0 to 6.1.1 has a critical security issue on attachment uploads (this is fixed in Joomla 6.1.2).

That means iCagenda running on all older versions prior to Joomla 6 (and all J6 version since 6.1.2) don't have a critical vulnerability.

The only common issue is the possibility to submit a not-approved event in guest access. The result is "fake" event added to the list of events, not visible on public frontend, but in admin, and with no possibility to exploit it.
So, more annoying than anything.

About your pro version, the version 3.6.6 is really old. If you don't have anymore an active pro subscription, so you can't update to pro.
If you want to install the free version over a pro version, then you will have first to remove the pro module (iC Event List) and the pro plugins, as it's using old code from 3.6.6 (December 2016... 10 years ago) may not run with component code from 2026...
This is like installing a core component of Joomla 6 on a Joomla 3 site, it will crash.

Another solution, if you want to keep the pro feature of iCagenda Pro, is to renew your subscription... ;-)

Best regards,
Cyril

Latest version : iCagenda 4.0.11
We recommend every user to keep iCagenda updated.
Don't forget to have your Joomla!™ up-to-date!

Do you like iCagenda?
I would appreciate if you could take 5 minutes to post a review on JED (Joomla Extensions Directory) .

File allegato:

Ultima Modifica 3 Settimane 2 giorni fa da Lyr!C.

Si prega Accedi o Crea un account a partecipare alla conversazione.

  • Sinna
  • Autore della discussione
  • New Member
  • New Member
Di più
3 Settimane 3 giorni fa #19093 da Sinna
Risposta da Sinna al topic CVE-2026-48939
Thanks for your swift response and confirming 'my' ancient version is not vulnerable.

I'm still somehow confused as www.icagenda.com/docs/changelog/icagenda-3-9-15 mentions 3.9.15 is Joomla! 3 Security Release, so I would expect earlier versions are vulnerable.

Can you clarify on this? Thanks!

I asked the original web developer but he couldn't remember to have bought this plugin (indeed 10 years ago).

Kind regards,
Kris

Computer[h|z]ero

Si prega Accedi o Crea un account a partecipare alla conversazione.

  • Lyr!C
  • Avatar di Lyr!C
  • Administrator
  • Administrator
  • Lead Developer
Di più
3 Settimane 3 giorni fa #19098 da Lyr!C
Risposta da Lyr!C al topic CVE-2026-48939
Hello,

Yes it's a security release as it adds a few security improvements.
When i released it, i was still investigating about why this issue happened, and i was not yet sure the critical issue was only on Joomla 6.0.0 to 6.1.1 due to a change (regression) in the Joomla framework (fixed in Joomla 6.1.2).

At least, 3.9.15 is blocking the submission of events from frontend in guest access (even if events were not approved and not visible in the frontend, this was an annoying issue for users. And even if not exploitable, it's is still a security fix as what is not supposed to be allowed should not be allowed).

In all cases, it's always better to keep a Joomla up-to-date as well as all extensions installed. And when an extension development is abandonned, it's better to find as soon as possible another extension to replace it.

Another recommendation is to full uninstall extensions that are not anymore used.

But as you're on Joomla 3, my first recommendation would be to clean your site of what not used, and upgrade to J4 and then J5 at minimum.

With AI, web and computer faster, the bots build to hack websites (all type of platforms are concerned), it's important more than ever to keep your own website up-to-date, protected and to do regularly backups.

I know upgrade from J3 to J4 is not easy, but after that, upgrade from J4 to J5 to J6 and later is much more easy than ever! (which was the goal of the massive code structure change in Joomla 4).

Best regards,
Cyril

Latest version : iCagenda 4.0.11
We recommend every user to keep iCagenda updated.
Don't forget to have your Joomla!™ up-to-date!

Do you like iCagenda?
I would appreciate if you could take 5 minutes to post a review on JED (Joomla Extensions Directory) .

File allegato:

Ringraziano per il messaggio: Sinna

Si prega Accedi o Crea un account a partecipare alla conversazione.

  • mark_12
  • New Member
  • New Member
Di più
3 Settimane 2 giorni fa #19099 da mark_12
Risposta da mark_12 al topic CVE-2026-48939
"The only common issue is the possibility to submit a not-approved event in quest access. The result is "fake" event added to the list of events, not visible on public frontend, but in admin, and with no possibility to exploit it."

How can I fix it? Simply update icagenda?
But aren't there any php files or traces of the attack left in the database? Does anyone have any idea if, and if so, which malicious files remain in the module files even after the update?

Si prega Accedi o Crea un account a partecipare alla conversazione.

  • Sinna
  • Autore della discussione
  • New Member
  • New Member
Di più
3 Settimane 2 giorni fa #19100 da Sinna
Risposta da Sinna al topic CVE-2026-48939
Thanks for the elaborated response.
This gives me confidence upgrading to 3.9.15 is not applicable in my case.

Kind regards,
Kris

Computer[h|z]ero

Si prega Accedi o Crea un account a partecipare alla conversazione.

  • Lyr!C
  • Avatar di Lyr!C
  • Administrator
  • Administrator
  • Lead Developer
Di più
3 Settimane 2 giorni fa #19101 da Lyr!C
Risposta da Lyr!C al topic CVE-2026-48939

"The only common issue is the possibility to submit a not-approved event in quest access. The result is "fake" event added to the list of events, not visible on public frontend, but in admin, and with no possibility to exploit it."

How can I fix it? Simply update icagenda?
But aren't there any php files or traces of the attack left in the database? Does anyone have any idea if, and if so, which malicious files remain in the module files even after the update?
 
Hello Mark,
Yes, just update.
If your site was not on Joomla 6.0.0 to 6.1.1 before update of iCagenda, you don't have to worry about iCagenda. No file could be uploaded.
As i've explained already in the blog article: www.joomlic.com/news/icagenda-security-update
And in my previous message here: forum.joomlic.com/icagenda-help-en/4921-cve-2026-48939#19098

If you have suspicious files (php or else) in your Joomla install, this is not due to iCagenda, so better to invest if it's not due to another extension, or if on an old not supported Joomla version (like Joomla 3 and 4).

Best regards,
Cyril

 

Latest version : iCagenda 4.0.11
We recommend every user to keep iCagenda updated.
Don't forget to have your Joomla!™ up-to-date!

Do you like iCagenda?
I would appreciate if you could take 5 minutes to post a review on JED (Joomla Extensions Directory) .

File allegato:

Si prega Accedi o Crea un account a partecipare alla conversazione.

Moderatori: Lyr!C
Tempo creazione pagina: 0.141 secondi

Follow Us

Create your Joomla templates with Template Creator CK

acymailing logo new