iCagenda – critical unauthenticated file upload
Secure version: iCagenda 4.0.8 · free download
At a glance
What is this about?
iCagenda is a widely used extension for event calendars. The form for submitting events lacked a real login check. As a result, even unauthenticated attackers could upload files – even when the form was actually intended for registered users only.
Affected are all versions before 4.0.8 (in particular 4.0.7 and older). The fix iCagenda 4.0.8 was released on 15 June 2026. A CVE number had not yet been publicly assigned at the time of the report.
Uploaded files typically end up under images/icagenda/frontend/. An .htaccess rule can prevent PHP execution in this folder – a sensible hardening measure, but it does not replace the update.
Am I affected? – How to check
- Open the back end
Log in to the Joomla administrator.
- Check the iCagenda version
Open Extensions›Manage›Manage and filter for "iCagenda".
- Assess the version
If the version is below 4.0.8, action is urgently needed.
How to fix it
- Open the Update center
Go to System›Update›Extensions and click Check for updates.
- Update iCagenda
Select the iCagenda entry and click Update (target version 4.0.8).
- Verify the version
Confirm that 4.0.8 is now installed.
Official source: free download. Make sure you have at least iCagenda 4.0.8.
Has the site already been attacked?
images/icagenda/frontend/ for foreign files. If compromised, a structured clean-up is required – simply deleting individual files is not enough.Sources & further reading
- Detailed analysis – Website-Bereinigung.deBackground, hardening, clean-up
- iCagenda (vendor)Official downloads
The official information from the respective vendor always takes precedence. This page neutrally summarises publicly available information.
Supporters of this site
htprotect.org is a free, vendor-independent information service. It is supported by:

Joomla host from Germany with active community support – discovered the first attack on the JCE vulnerability.
fc-hosting.deSpecialised in cleaning, maintaining and securing Joomla and WordPress websites.
website-bereinigung.deSupport this project
You run a hosting or Joomla service and would like to support htprotect.org – and be listed here as a supporter? Every contribution helps to warn and protect those affected faster.