CVE-2026-48939CISA KEVEPSS p97.6%

CVE-2026-48939iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability

iCagenda / iCagenda

Description

iCagenda contains an unrestricted upload of file with dangerous type vulnerability that allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.

Scoring

CVSS 9.8 ()
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS24.35% probability of exploitation · percentile 97.6% · 2026-08-04T12:00:14Z
Last modified2026-07-11

CISA KEV entry

Added to KEV: 2026-07-10

Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.