Skip to main content
mySites.guru
New features added last monthRelease RadarFile ManagerImpostor FilesUpdate QueueRogue AdminsMCP & APIJoomla VELCVE Index
CVE-2026-78070MediumPublished 28 August 2026

DPCalendar (com_dpcalendar) 5.5.0 to 8.19.4 (Joomla 3) - Authenticated Blind SQL Injection

DPCalendar contains a blind SQL injection reachable by saving a Joomla article. The DPCalendar content plugin passes the order and orderdir parameters of a {dpcalendar} tag into the events query ORDER BY clause without validating them against the model filter_fields allow-list. The sink used the database escape() helper, which secures string literals but not SQL identifiers, so the sort column is injectable. Exploitation requires an account holding permission to create or update articles, so this is authenticated and privileged (CVSS 4.0 vector PR:H), not anonymous. Reported by Toan Le as vendor issue 12206. Fixed in 10.12.0 on the Joomla 4 to 6 branch and backported to 8.19.5 on the Joomla 3 branch. Temporary mitigation: disable the "Content - DPCalendar" plugin, which is the only route in.

Affected versions: ≥ 5.5.0 and < 8.19.5

Official record: cve.org · NVD

Every connected Joomla site is checked against these rules on each audit, and flagged if it runs an affected version.

Affected extensions and versions

MediumCVE-2026-780702026-08-28

DPCalendar - DPCalendar (com_dpcalendar) 9.0.0 to 10.11.2 (Joomla 4 to 6) - Authenticated Blind SQL Injection

DPCalendar contains a blind SQL injection reachable by saving a Joomla article. The DPCalendar content plugin passes the order and orderdir parameters of a {dpcalendar} tag into the events query ORDER BY clause without validating them against the model filter_fields allow-list. The sink used the database escape() helper, which secures string literals but not SQL identifiers, so the sort column is injectable. Exploitation requires an account holding permission to create or update articles, so this is authenticated and privileged (CVSS 4.0 vector PR:H), not anonymous. Reported by Toan Le as vendor issue 12206. Fixed in 10.12.0 on the Joomla 4 to 6 branch and backported to 8.19.5 on the Joomla 3 branch. Temporary mitigation: disable the "Content - DPCalendar" plugin, which is the only route in.

Affected versions: ≥ 9.0.0 and ≤ 10.11.2

Full advisory: joomla.digital-peak.com

Running an affected version on a site you manage?

A free audit tells you which of your Joomla and WordPress sites run an affected version, which are out of date, and which have not been backed up. No card required. If a site is already compromised, fix.mysites.guru is a single fixed fee per incident, usually resolved the same day.

Rules current as of 13 September 2026.