NONE · 0

CVE-2026-77989

Joomla Extension - joomlaeventmanager.net - Reflected XSS via the PDF export link in Joomla Events Manager < 5.0.1 - buildCurrentPdfLink copies the current request query string into the PDF button URL...

Vulnerability Description

Joomla Extension - joomlaeventmanager.net - Reflected XSS via the PDF export link in Joomla Events Manager < 5.0.1 - buildCurrentPdfLink copies the current request query string into the PDF button URL, and pdfbutton() echoes it unescaped, leading to an reflected XSS vector.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-77989?

CVE-2026-77989 is a documented vulnerability. Joomla Extension - joomlaeventmanager.net - Reflected XSS via the PDF export link in Joomla Events Manager < 5.0.1 - buildCurrentPdfLink copies the current request query string into the PDF button URL...

How severe is CVE-2026-77989?

CVSS scoring is not yet available for CVE-2026-77989. Check NVD for updates.

Is there a patch for CVE-2026-77989?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.