CVE-2026-77034
Joomla Extension - joomlaeventmanager.net - Unauthenticated article overwrite and force-publish in Joomla Event Manager < 5.0.1 - Any visitor holding their own session token can republish and overwrite an article associated with an event.
- Published Aug 27, 2026
- CVSS 6.9 medium
- 0.4% chance of exploitation in the next 30 days (EPSS)