Security
DPCalendar reports serious read-only database access flaw
Digital Peak has reported a serious vulnerability in its DPCalendar event-calendar component that can enable unauthorised access to data stored in a Joomla database. The issue is limited to reading data and does not allow attackers to…
The vulnerability was reported to the Digital Peak team on 12 July 2026. The available information classifies the issue as serious and indicates that exploitation can expose database contents through DPCalendar.
Digital Peak says the weakness is read-only: an attacker cannot use it to alter or update data. That limitation does not remove the need for prompt remediation, since database access can still expose information held by a Joomla site.
Update paths
Updates can be applied through Joomla’s update manager or by downloading the relevant package manually from Digital Peak. The referenced download for the current release is DPCalendar 10.11.2. A separate package, DPCalendar 8.19.4, is provided for sites running Joomla 3.x.
- DPCalendar 10.11.2:
https://joomla.digital-peak.com/download/dpcalendar/dpcalendar-10.11.2 - DPCalendar 8.19.4 for Joomla 3.x:
https://joomla.digital-peak.com/download/dpcalendar/dpcalendar-8.19.4
The source notice does not provide a CVE identifier or technical details about the vulnerable code. Site operators should check the installed DPCalendar version and apply the appropriate update without delay.