CVE-2026-60025

CVE-2026-60025: Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0

Vendor Joomdonation.com
Product Events Booking extension for Joomla
Weakness CWE-352 · CSRF
Published July 17, 2026
Last update August 12, 2026

CVSS base score

What the vulnerability does

01Description

Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0 - The Joomla extension Events Booking prior version 5.8.0 had an frontend file upload endpoint that lacked CSRF protection.

Key dates

02Disclosure timeline

July 17, 2026 CVE published
August 12, 2026 Record updated

Related vulnerabilities

04Related CVE