Skip to main content
mySites.guru
New features added last monthRelease RadarFile ManagerImpostor FilesUpdate QueueRogue AdminsMCP & APIJoomla VELCVE Index
CVE-2026-78071HighPublished 28 August 2026

DPCalendar (com_dpcalendar) 7.0.0 to 8.19.5 (Joomla 3) - Authenticated Stored Cross-Site Scripting

DPCalendar renders a calendar location title into a data-title HTML attribute without escaping it, giving a stored cross-site scripting flaw. A payload such as x" onmouseover="alert(1) has no HTML tags, so it passes through the filterText input filter unchanged and breaks out of the attribute on output, where it becomes a live event handler. Storing the payload requires an account with DPCalendar location create permission (CVSS 4.0 vector PR:H), but the script then runs in the browser of every visitor who views that location page, so the permission bounds who can plant it and not who it hits. This was reported in two stages. Toan Le found the original as vendor issue 12203, fixed on 2026-08-27 in 8.19.5 and 10.12.0, which escaped nine of the ten data-title sinks in the component. mySites.guru proved the same day that the tenth was still open, at components/com_dpcalendar/site/tmpl/location/default_map.php line 23, reported it to Digital Peak and the Joomla Security Strike Team, and Digital Peak confirmed it on 2026-08-28. That last sink was closed on 2026-09-10 in 8.19.6 and 10.12.1, along with seven identical sinks in the free mod_dpcalendar_upcoming module templates (blog, default, horizontal, icon, panel, simple and timeline). CVE-2026-78071 was updated on 2026-09-10 to widen its affected range to 7.0.0-8.19.5 and 9.0.0-10.12.0 and to credit both finders. On Joomla 3 the fixed version is 8.19.6, which is a security-only release containing this one change. If you have overridden the DPCalendar location templates, the unescaped output is still in your override and updating the extension will not reach it.

Affected versions: ≥ 7.0.0 and < 8.19.6

Official record: cve.org · NVD

Every connected Joomla site is checked against these rules on each audit, and flagged if it runs an affected version.

Affected extensions and versions

HighCVE-2026-780712026-08-28

DPCalendar - DPCalendar (com_dpcalendar) 9.0.0 to 10.12.0 (Joomla 4 to 6) - Authenticated Stored Cross-Site Scripting

DPCalendar renders a calendar location title into a data-title HTML attribute without escaping it, giving a stored cross-site scripting flaw. A payload such as x" onmouseover="alert(1) has no HTML tags, so it passes through the filterText input filter unchanged and breaks out of the attribute on output, where it becomes a live event handler. Storing the payload requires an account with DPCalendar location create permission (CVSS 4.0 vector PR:H), but the script then runs in the browser of every visitor who views that location page, so the permission bounds who can plant it and not who it hits. This was reported in two stages. Toan Le found the original as vendor issue 12203, fixed on 2026-08-27 in 8.19.5 and 10.12.0, which escaped nine of the ten data-title sinks in the component. mySites.guru proved the same day that the tenth was still open, at components/com_dpcalendar/site/tmpl/location/default_map.php line 23, reported it to Digital Peak and the Joomla Security Strike Team, and Digital Peak confirmed it on 2026-08-28. That last sink was closed on 2026-09-10 in 8.19.6 and 10.12.1, along with seven identical sinks in the free mod_dpcalendar_upcoming module templates (blog, default, horizontal, icon, panel, simple and timeline). CVE-2026-78071 was updated on 2026-09-10 to widen its affected range to 7.0.0-8.19.5 and 9.0.0-10.12.0 and to credit both finders. Update to 10.12.1 on Joomla 4, 5 and 6. The 9.x line has no patch of its own, so sites there need the staged upgrade across to 10.12.1 rather than a point update. If you have overridden the DPCalendar location templates, the unescaped output is still in your override and updating the extension will not reach it.

Affected versions: ≥ 9.0.0 and < 10.12.1

Full advisory: our disclosure post

Our disclosure post

Running an affected version on a site you manage?

A free audit tells you which of your Joomla and WordPress sites run an affected version, which are out of date, and which have not been backed up. No card required. If a site is already compromised, fix.mysites.guru is a single fixed fee per incident, usually resolved the same day.

Rules current as of 11 September 2026.