Joomla Extension - digital-peak.com - Authenticated, privileged stored XSS in DP Calendar 7.0.0-8.19.5, 9.0.0-10.12.0 - Location title is rendered in data attribute without escaping leads to XSS, needs create permission in DPCalendar.
History

Thu, 10 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Description Joomla Extension - digital-peak.com - Authenticated, privileged stored XSS in DP Calendar 7.0.0 - 10.11.2 - Location title is rendered in data attribute without escaping leads to XSS, needs create permission in DPCalendar. Joomla Extension - digital-peak.com - Authenticated, privileged stored XSS in DP Calendar 7.0.0-8.19.5, 9.0.0-10.12.0 - Location title is rendered in data attribute without escaping leads to XSS, needs create permission in DPCalendar.
Title Joomla Extension - digital-peak.com - Authenticated, privileged stored XSS in DP Calendar 7.0.0 - 10.11.2 Joomla Extension - digital-peak.com - Authenticated, privileged stored XSS in DP Calendar 7.0.0-8.19.5, 9.0.0-10.12.0

Tue, 01 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Digital-peak
Digital-peak dp Calendar For Joomla
Vendors & Products Digital-peak
Digital-peak dp Calendar For Joomla

Fri, 28 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 28 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
Description Joomla Extension - digital-peak.com - Authenticated, privileged stored XSS in DP Calendar 7.0.0 - 10.11.2 - Location title is rendered in data attribute without escaping leads to XSS, needs create permission in DPCalendar.
Title Joomla Extension - digital-peak.com - Authenticated, privileged stored XSS in DP Calendar 7.0.0 - 10.11.2
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 7.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/S:N/AU:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published: 2026-08-28T07:49:52.253Z

Updated: 2026-09-10T10:45:13.877Z

Reserved: 2026-08-22T14:23:37.800Z

Link: CVE-2026-78071

cve-icon Vulnrichment

Updated: 2026-08-28T15:04:55.966Z

cve-icon NVD

Status : Deferred

Published: 2026-08-28T12:16:31.827

Modified: 2026-09-10T11:17:07.223

Link: CVE-2026-78071

cve-icon Redhat

No data.