CVE-2026-63047
Deferred Deferred - Pending Action

Unauthorized Invoice Download in Events Booking Extension

Vulnerability report for CVE-2026-63047, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-22

Last updated on: 2026-07-23

Assigner: Joomla! Project

Description

Joomla Extension - joomdonation.com - Invoice data exfiltration via incorrect ACL check in Events Booking 5.0.0-5.8.1 - The Joomla extension Events Booking prior version 5.0-5.8.1 did not properly verify that an actor is allowed to download invoice information.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-22
Last Modified
2026-07-23
Generated
2026-08-11
AI Q&A
2026-07-22
EPSS Evaluated
2026-08-10
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
joomla events_booking to 5.8.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Joomla extension Events Booking prior to version 5.8.1 has a vulnerability where it fails to properly verify if a user is authorized to download invoice information. This could allow unauthorized access to sensitive data.

Detection Guidance

This vulnerability involves unauthorized access to invoice information in the Events Booking Joomla extension. To detect it, check for unusual downloads of invoice data or unauthorized access to user information through Joomla logs. Inspect network traffic for requests to paths like /index.php?option=com_eventbooking&view=invoice. Ensure the extension is updated to version 5.8.1 or later.

Impact Analysis

This vulnerability could lead to unauthorized access to invoice data, potentially exposing personal or financial information of users who registered for events through the extension.

Compliance Impact

This vulnerability could result in non-compliance with data protection regulations like GDPR or HIPAA if it leads to unauthorized access or exposure of personal data, potentially resulting in legal penalties or reputational damage.

Mitigation Strategies

Update the Events Booking Joomla extension to version 5.8.1 or later immediately to address the unauthorized invoice download vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-63047. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart