Affected versions: ≥ 5.5.0 and < 8.19.5
Full advisory: joomla.digital-peak.com
DPCalendar contains a blind SQL injection reachable by saving a Joomla article. The DPCalendar content plugin passes the order and orderdir parameters of a {dpcalendar} tag into the events query ORDER BY clause without validating them against the model filter_fields allow-list. The sink used the database escape() helper, which secures string literals but not SQL identifiers, so the sort column is injectable. Exploitation requires an account holding permission to create or update articles, so this is authenticated and privileged (CVSS 4.0 vector PR:H), not anonymous. Reported by Toan Le as vendor issue 12206. Fixed in 10.12.0 on the Joomla 4 to 6 branch and backported to 8.19.5 on the Joomla 3 branch. Temporary mitigation: disable the "Content - DPCalendar" plugin, which is the only route in.
Affected versions: ≥ 5.5.0 and < 8.19.5
Official record: cve.org · NVD
Every connected Joomla site is checked against these rules on each audit, and flagged if it runs an affected version.
Affected versions: ≥ 5.5.0 and < 8.19.5
Full advisory: joomla.digital-peak.com
DPCalendar - DPCalendar (com_dpcalendar) 9.0.0 to 10.11.2 (Joomla 4 to 6) - Authenticated Blind SQL Injection
DPCalendar contains a blind SQL injection reachable by saving a Joomla article. The DPCalendar content plugin passes the order and orderdir parameters of a {dpcalendar} tag into the events query ORDER BY clause without validating them against the model filter_fields allow-list. The sink used the database escape() helper, which secures string literals but not SQL identifiers, so the sort column is injectable. Exploitation requires an account holding permission to create or update articles, so this is authenticated and privileged (CVSS 4.0 vector PR:H), not anonymous. Reported by Toan Le as vendor issue 12206. Fixed in 10.12.0 on the Joomla 4 to 6 branch and backported to 8.19.5 on the Joomla 3 branch. Temporary mitigation: disable the "Content - DPCalendar" plugin, which is the only route in.
Affected versions: ≥ 9.0.0 and ≤ 10.11.2
Full advisory: joomla.digital-peak.com
A free audit tells you which of your Joomla and WordPress sites run an affected version, which are out of date, and which have not been backed up. No card required. If a site is already compromised, fix.mysites.guru is a single fixed fee per incident, usually resolved the same day.
Rules current as of 13 September 2026.