CVE-2026-78071
Joomla Extension - digital-peak.com - Authenticated, privileged stored XSS in DP Calendar 7.0.0-8.19.5, 9.0.0-10.12.0 - Location title is rendered in data attribute without escaping leads to XSS, needs create permission in DPCalendar.
- Published Aug 28, 2026
- CVSS 7.5 high
- 0.4% chance of exploitation in the next 30 days (EPSS)