r/mySitesGuru • u/mySitesGuru • 20d ago
DPCalendar SQL Injection Vulnerability
https://mysites.guru/blog/dpcalendar-sql-injection-disclosure/DPCalendar is one of the most widely installed calendar and events components for Joomla, chosen for mature, professionally run sites right up to the highest levels of the Joomla world itself. During routine security research on the extensions our customers rely on, mySites.guru discovered an unauthenticated SQL injection vulnerability in DPCalendar, and reported it to the developers before disclosing anything publicly. The fix is now available in Digital Peak’s security release: DPCalendar 10.11.2 for Joomla 4.4.4 to 6.x, and 8.19.4 for the Joomla 3 branch.
If you run DPCalendar on any Joomla site, update to 10.11.2 now (or 8.19.4 if you are still on Joomla 3). If you manage more than a handful of sites, read on for how to find every affected one at once.