GHSA-2rwc-gxjj-fh85HighCVSS 8.2

Joomla! Component Calendar Planner 1.0.1 contains an SQL injection vulnerability that allows...

Published
June 19, 2026
Last Modified
June 19, 2026

🔗 CVE IDs covered (1)

📋 Description

Joomla! Component Calendar Planner 1.0.1 contains an SQL injection vulnerability that allows unauthenticated attackers to inject SQL commands through the category_id parameter. Attackers can send GET requests to the events view with malicious SQL code in the category_id parameter to extract sensitive database information.

🔗 References (6)