CVE-2026-48939: iCagenda Unrestricted Upload of File with Dangerous Type
iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability. iCagenda contains an unrestricted upload of file with dangerous type vulnerability that allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.
- CISA KEV-listed (remediation due 2026-07-13)
- EPSS 24.3% (97.6% percentile)
- CVSS 10 critical