Description

The Joomla extension Events Booking prior version 5.8.0 had an frontend file upload endpoint that lacked CSRF protection.

Weaknesses

  • CWE-352 — CWE-352 Cross-Site Request Forgery (CSRF)

Affected products

VendorProductVersions
joomdonation.comEvents Booking extension for Joomla1.0-5.8.0

References

Authoritative sources

This page is a snapshot. For the latest enrichment and updates, view the record on CVE.org or the NVD.

Generated from the official CVE List on 18 Jul 2026 07:00 UTC.