CVE-2026-78071
moderateStored XSS in Digital Peak DPCalendar for Joomla via unescaped location title
DPCalendar, a calendar extension for Joomla by Digital Peak, stores calendar location titles and later renders them inside an HTML data attribute without escaping, allowing injected markup to break out of the attribute. An authenticated user who holds the DPCalendar create permission can save a maliciously crafted location title, and the payload executes as JavaScript in the browsers of any user who views a page that displays that location. Successful exploitation lets the attacker run script in another user's Joomla session, enabling actions within that user's privileges such as content manipulation or session token theft, while the CVSS 4.0 score of 7.5 (high) reflects the privileged access requirement and high confidentiality/integrity impact. Affected deployments are Joomla sites running DPCalendar 7.0.0 through 8.19.5 or 9.0.0 through 10.12.0. No public proof-of-concept exists, the flaw is not in the CISA KEV catalog, and EPSS puts 30-day exploitation probability at only 0.3%, so no exploitation is currently known.
What to do: Update DPCalendar to a release newer than 10.12.0 (i.e., the fixed version published in the Digital Peak/Joomla advisory). As interim mitigation, limit DPCalendar create permission to trusted users only, since exploiting the flaw requires that privilege, and audit existing calendar location titles for embedded HTML, quotes, or script payloads.
| Digital Peak (digital-peak.com) DPCalendar (DP Calendar) Joomla extension | 7.0.0 - 8.19.5 |
| Digital Peak (digital-peak.com) DPCalendar (DP Calendar) Joomla extension | 9.0.0 - 10.12.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Joomla Extension - digital-peak.com - Authenticated, privileged stored XSS in DP Calendar 7.0.0-8.19.5, 9.0.0-10.12.0 - Location title is rendered in data attribute without escaping leads to XSS, needs create permission in DPCalendar.
- Ecosystems
- Joomla
- Weakness
- CWE-79
- Vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.