iCagenda – critical unauthenticated file upload
Secure version: iCagenda 4.0.8 (Joomla 3: 3.9.15) · free download
At a glance
What is this about?
iCagenda is a widely used extension for event calendars. The form for submitting events lacked a real login check – so even unauthenticated visitors could create events, even when the form was intended for registered users only. On Joomla 6 (6.0.0–6.1.1) this can be turned into a file upload – there the flaw is critical; other Joomla versions are not affected by that.
Affected is iCagenda 3.2.1 to 4.0.7 (versions before 3.2.1 are not affected). The fix shipped as iCagenda 4.0.8 on 15 June 2026; for Joomla 3 there is additionally iCagenda 3.9.15 (16 June 2026). The flaw is tracked as CVE-2026-48939.
Uploaded files typically end up under images/icagenda/frontend/. An .htaccess rule can prevent PHP execution in this folder – a sensible hardening measure, but it does not replace the update.
Am I affected? – How to check
- Open the back end
Log in to the Joomla administrator.
- Check the iCagenda version
Open Extensions›Manage›Manage and filter for "iCagenda".
- Assess the version
If the version is between 3.2.1 and 4.0.7, action is needed – on Joomla 6 the flaw is critical.
How to fix it
- Open the Update center
Go to System›Update›Extensions and click Check for updates.
- Update iCagenda
Select the iCagenda entry and click Update (target version 4.0.8; on Joomla 3, 3.9.15).
- Verify the version
Confirm that 4.0.8 (or 3.9.15 on Joomla 3) or newer is now installed.
Official source: free download. Make sure you have at least iCagenda 4.0.8 (Joomla 3: 3.9.15).
Has the site already been attacked?
images/icagenda/frontend/ for foreign files. If compromised, a structured clean-up is required – simply deleting individual files is not enough.Need help with the clean-up? Find qualified specialists in the Joomla Service Providers Directory.
Sources & further reading
- Official security advisory – iCagenda (joomlic.com)Vendor advisory: affected versions, fixes, CVE
- Detailed analysis – Website-Bereinigung.deBackground, hardening, clean-up
- iCagenda (vendor)Official downloads
The official information from the respective vendor always takes precedence. This page neutrally summarises publicly available information.
Supporters of this site
htprotect.org is a free, vendor-independent information service. It is supported by:

Joomla host from Germany with active community support – discovered the first attack on the JCE vulnerability.
fc-hosting.deSpecialised in cleaning, maintaining and securing Joomla and WordPress websites.
website-bereinigung.deSupport this project
You run a hosting or Joomla service and would like to support htprotect.org – and be listed here as a supporter? Every contribution helps to warn and protect those affected faster.
Prefer to give privately, without a listing? A little something for the tip jar is just as welcome.
Manufactures and installs construction-site signs, hoardings and façade solutions – including design and 3D visualisation.
bauschildundservice.deProfessional IT support from Czechia – Windows management, domain administration and web hosting.
defendersoft.czTravel portal from Germany – package holidays, hotels and flights online, with personal travel-agency advice.
onlineweg.deCreative agency from Brandenburg – web design, print media, photography and 360° panoramas from a single source.
criadero.deIT service provider from Wächtersbach – Joomla websites, PC service, hardware and software.
jahnedv.deInformation-security consulting from Berlin – security analyses, risk management and ISO 27001 for SMEs.
isari-consult.de