CVE-2026-77989 UNKNOWN

CVE-2026-77989

Published: 2026-08-27

Description

Joomla Extension - joomlaeventmanager.net - Reflected XSS via the PDF export link in Joomla Events Manager < 5.0.1 - buildCurrentPdfLink copies the current request query string into the PDF button URL, and pdfbutton() echoes it unescaped, leading to an reflected XSS vector.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…