iCagenda – critical unauthenticated file upload
Secure version: iCagenda 4.0.8 (Joomla 3: 3.9.15) · free download
At a glance
What is this about?
iCagenda is a widely used extension for event calendars. The form for submitting events lacked a real login check – so even unauthenticated visitors could create events, even when the form was intended for registered users only. On Joomla 6 (6.0.0–6.1.1) this can be turned into a file upload – there the flaw is critical; other Joomla versions are not affected by that.
Affected is iCagenda 3.2.1 to 4.0.7 (versions before 3.2.1 are not affected). The fix shipped as iCagenda 4.0.8 on 15 June 2026; for Joomla 3 there is additionally iCagenda 3.9.15 (16 June 2026). The flaw is tracked as CVE-2026-48939.
Uploaded files typically end up under images/icagenda/frontend/. An .htaccess rule can prevent PHP execution in this folder – a sensible hardening measure, but it does not replace the update.
Am I affected? – How to check
- Open the back end
Log in to the Joomla administrator.
- Check the iCagenda version
Open Extensions›Manage›Manage and filter for "iCagenda".
- Assess the version
If the version is between 3.2.1 and 4.0.7, action is needed – on Joomla 6 the flaw is critical.
How to fix it
- Open the Update center
Go to System›Update›Extensions and click Check for updates.
- Update iCagenda
Select the iCagenda entry and click Update (target version 4.0.8; on Joomla 3, 3.9.15).
- Verify the version
Confirm that 4.0.8 (or 3.9.15 on Joomla 3) or newer is now installed.
Official source: free download. Make sure you have at least iCagenda 4.0.8 (Joomla 3: 3.9.15).
Has the site already been attacked?
images/icagenda/frontend/ for foreign files. If compromised, a structured clean-up is required – simply deleting individual files is not enough.Need help with the clean-up? Find qualified specialists in the Joomla Service Providers Directory.
Sources & further reading
- Official security advisory – iCagenda (joomlic.com)Vendor advisory: affected versions, fixes, CVE
- Detailed analysis – Website-Bereinigung.deBackground, hardening, clean-up
- iCagenda (vendor)Official downloads
The official information from the respective vendor always takes precedence. This page neutrally summarises publicly available information.
Related vulnerabilities
Other extensions with comparable weaknesses. Check whether any of them is installed on your site.
Supporters of this site
htprotect.org is a free, vendor-independent information service. It is supported by:

Joomla host from Germany with active community support – discovered the first attack on the JCE vulnerability.
fc-hosting.deSpecialised in cleaning, maintaining and securing Joomla and WordPress websites.
website-bereinigung.deSupport this project
You run a hosting or Joomla service and would like to support htprotect.org – and be listed here as a supporter? Every contribution helps to warn and protect those affected faster.
Prefer to give privately, without a listing? A little something for the tip jar is just as welcome.
Manufactures and installs construction-site signs, hoardings and façade solutions – including design and 3D visualisation.
bauschildundservice.deProfessional IT support from Czechia – Windows management, domain administration and web hosting.
defendersoft.czTravel portal from Germany – package holidays, hotels and flights online, with personal travel-agency advice.
onlineweg.deCreative agency from Brandenburg – web design, print media, photography and 360° panoramas from a single source.
criadero.deIT service provider from Wächtersbach – Joomla websites, PC service, hardware and software.
jahnedv.deInformation-security consulting from Berlin – security analyses, risk management and ISO 27001 for SMEs.
isari-consult.de
Media design from Friedrichshafen – Joomla and WordPress sites, online shops, graphics and 3D.
schippelbein.com