LOWVulnerability

CVE-2026-78071

Joomla Extension - digital-peak.com - Authenticated, privileged stored XSS in DP Calendar 7.0.0-8.19.5, 9.0.0-10.12.0 - Location title is rendered in data attribute without escaping leads to XSS, needs create permission in DPCalendar.

Properties

epss_score
0.00304
cve_id
CVE-2026-78071
signal_observed_at
2026-09-15T21:12:47+00:00
published_at
2026-08-28T12:16:31.827
last_modified
2026-09-10T11:17:07.223
epss_percentile
0.23038

Related Entities (3)

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (1)

[Weakness]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-78071 — Ninja Signal Threat Intelligence | Ninja Signal