ZeroHour

CVE-2026-78071

moderate

Stored XSS in Digital Peak DPCalendar for Joomla via unescaped location title

CVSS 4.0
7.5 high
EPSS
<1%p23
Published
()
Modified
AI analysis

DPCalendar, a calendar extension for Joomla by Digital Peak, stores calendar location titles and later renders them inside an HTML data attribute without escaping, allowing injected markup to break out of the attribute. An authenticated user who holds the DPCalendar create permission can save a maliciously crafted location title, and the payload executes as JavaScript in the browsers of any user who views a page that displays that location. Successful exploitation lets the attacker run script in another user's Joomla session, enabling actions within that user's privileges such as content manipulation or session token theft, while the CVSS 4.0 score of 7.5 (high) reflects the privileged access requirement and high confidentiality/integrity impact. Affected deployments are Joomla sites running DPCalendar 7.0.0 through 8.19.5 or 9.0.0 through 10.12.0. No public proof-of-concept exists, the flaw is not in the CISA KEV catalog, and EPSS puts 30-day exploitation probability at only 0.3%, so no exploitation is currently known.

What to do: Update DPCalendar to a release newer than 10.12.0 (i.e., the fixed version published in the Digital Peak/Joomla advisory). As interim mitigation, limit DPCalendar create permission to trusted users only, since exploiting the flaw requires that privilege, and audit existing calendar location titles for embedded HTML, quotes, or script payloads.

Affected
Digital Peak (digital-peak.com) DPCalendar (DP Calendar) Joomla extension7.0.0 - 8.19.5
Digital Peak (digital-peak.com) DPCalendar (DP Calendar) Joomla extension9.0.0 - 10.12.0
Estimated exposure
moderateon the order of tens of thousands of Joomla sites at most (estimate, not a published count) — No install count was provided, so this is estimated from Joomla's small overall CMS market share (roughly 1-2% of websites) combined with DPCalendar's position as a popular but commercial paid calendar extension, implying only a fraction…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Joomla Extension - digital-peak.com - Authenticated, privileged stored XSS in DP Calendar 7.0.0-8.19.5, 9.0.0-10.12.0 - Location title is rendered in data attribute without escaping leads to XSS, needs create permission in DPCalendar.

Ecosystems
Joomla
Weakness
CWE-79
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.