Joomla Events Booking 5.05.8.1 Invoice Download Authorization Bypass
CVE-2026-63047 Published on July 22, 2026

Joomla Extension - joomdonation.com - Invoice data exfiltration via incorrect ACL check in Events Booking 5.0.0-5.8.1
The Joomla extension Events Booking prior version 5.0-5.8.1 did not properly verify that an actor is allowed to download invoice information.

NVD

Weakness Type

What is an Authorization Vulnerability?

The software does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

CVE-2026-63047 has been classified to as an Authorization vulnerability or weakness.


Affected Versions

joomdonation.com Events Booking extension for Joomla Version 5.0-5.8.1 is affected by CVE-2026-63047