A AegiFlow
UNKNOWNKNOWN EXPLOITED

CVE-2026-48939

iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability

Published
2026-07-10
Modified
2026-07-31
Sources
cisa-kev

Summary

iCagenda contains an unrestricted upload of file with dangerous type vulnerability that allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.

References

Includes data from the CISA Known Exploited Vulnerabilities catalog.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.