CVE-2026-63047

CVE-2026-63047: Joomla Extension - joomdonation.com - Invoice data exfiltration via incorrect ACL check in Events Booking 5.0.0-5.8.1

Vendor Joomdonation.com
Product Events Booking extension for Joomla
Weakness CWE-284
Published July 22, 2026
Last update July 23, 2026

CVSS base score

What the vulnerability does

01Description

Joomla Extension - joomdonation.com - Invoice data exfiltration via incorrect ACL check in Events Booking 5.0.0-5.8.1 - The Joomla extension Events Booking prior version 5.0-5.8.1 did not properly verify that an actor is allowed to download invoice information.

Key dates

02Disclosure timeline

July 22, 2026 CVE published
July 23, 2026 Record updated

Related vulnerabilities

04Related CVE