CVE-2026-77989EPSS p35.7%
CVE-2026-77989CVE-2026-77989
Description
Joomla Extension - joomlaeventmanager.net - Reflected XSS via the PDF export link in Joomla Events Manager < 5.0.1 - buildCurrentPdfLink copies the current request query string into the PDF button URL, and pdfbutton() echoes it unescaped, leading to an reflected XSS vector.
Scoring
| EPSS | 0.44% probability of exploitation · percentile 35.7% · 2026-10-05T12:00:23Z |
| Last modified | 2026-08-28 |