Description
The Joomla extension Events Booking prior version 5.8.0 had an frontend file upload endpoint that lacked CSRF protection.
Weaknesses
- CWE-352 — CWE-352 Cross-Site Request Forgery (CSRF)
Affected products
| Vendor | Product | Versions |
|---|---|---|
| joomdonation.com | Events Booking extension for Joomla | 1.0-5.8.0 |
References
Generated from the official CVE List on 18 Jul 2026 07:00 UTC.