Joomla Events Booking 5.05.8.1 Invoice Download Authorization Bypass
CVE-2026-63047 Published on July 22, 2026
Joomla Extension - joomdonation.com - Invoice data exfiltration via incorrect ACL check in Events Booking 5.0.0-5.8.1
The Joomla extension Events Booking prior version 5.0-5.8.1 did not properly verify that an actor is allowed to download invoice information.
Weakness Type
What is an Authorization Vulnerability?
The software does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CVE-2026-63047 has been classified to as an Authorization vulnerability or weakness.