Skip to main content
mySites.guru
New features added last monthRelease RadarFile ManagerImpostor FilesUpdate QueueRogue AdminsMCP & APIJoomla VELCVE Index
CVE-2026-78071HighPublished 28 August 2026

DPCalendar (com_dpcalendar) 7.0.0 to 8.19.4 (Joomla 3) - Authenticated Stored Cross-Site Scripting

DPCalendar renders a calendar location title into a data-title HTML attribute without escaping it, giving a stored cross-site scripting flaw. A payload such as x" onmouseover="alert(1) has no HTML tags, so it survives the input filter intact and breaks out of the attribute on output, where it becomes a live event handler. Storing the payload requires an account with DPCalendar location create permission (CVSS 4.0 vector PR:H), but the script then runs in the browser of every visitor who views that location page, so the permission bounds who can plant it and not who it hits. Reported by Toan Le as vendor issue 12203. IMPORTANT CAVEAT - THE VENDOR FIX IS INCOMPLETE. mySites.guru proved on 2026-08-27 that the 10.12.0 and 8.19.5 releases escaped nine data-title sinks but missed one, at components/com_dpcalendar/site/tmpl/location/default_map.php line 23, where the title is still echoed raw; the adjacent line 24 in the same file is correctly escaped. The filterText input filter added alongside the fix does not close it either, because filterText strips HTML tags and not quotes. Digital Peak confirmed this on 2026-08-28 and stated the remaining fix will ship in about a month. This rule deliberately follows the affected range stated in CVE-2026-78071, so sites already on 8.19.5 or 10.12.0 are NOT flagged here even though one instance of the same flaw is still present in those builds.

Affected versions: ≥ 7.0.0 and < 8.19.5

Official record: cve.org · NVD

Every connected Joomla site is checked against these rules on each audit, and flagged if it runs an affected version.

Affected extensions and versions

HighCVE-2026-780712026-08-28

DPCalendar - DPCalendar (com_dpcalendar) 9.0.0 to 10.11.2 (Joomla 4 to 6) - Authenticated Stored Cross-Site Scripting

DPCalendar renders a calendar location title into a data-title HTML attribute without escaping it, giving a stored cross-site scripting flaw. A payload such as x" onmouseover="alert(1) has no HTML tags, so it survives the input filter intact and breaks out of the attribute on output, where it becomes a live event handler. Storing the payload requires an account with DPCalendar location create permission (CVSS 4.0 vector PR:H), but the script then runs in the browser of every visitor who views that location page, so the permission bounds who can plant it and not who it hits. Reported by Toan Le as vendor issue 12203. IMPORTANT CAVEAT - THE VENDOR FIX IS INCOMPLETE. mySites.guru proved on 2026-08-27 that the 10.12.0 and 8.19.5 releases escaped nine data-title sinks but missed one, at components/com_dpcalendar/site/tmpl/location/default_map.php line 23, where the title is still echoed raw; the adjacent line 24 in the same file is correctly escaped. The filterText input filter added alongside the fix does not close it either, because filterText strips HTML tags and not quotes. Digital Peak confirmed this on 2026-08-28 and stated the remaining fix will ship in about a month. This rule deliberately follows the affected range stated in CVE-2026-78071, so sites already on 8.19.5 or 10.12.0 are NOT flagged here even though one instance of the same flaw is still present in those builds.

Affected versions: ≥ 9.0.0 and ≤ 10.11.2

Full advisory: joomla.digital-peak.com

Running an affected version on a site you manage?

A free audit tells you which of your Joomla and WordPress sites run an affected version, which are out of date, and which have not been backed up. No card required. If a site is already compromised, fix.mysites.guru is a single fixed fee per incident, usually resolved the same day.

Rules current as of 8 September 2026.