Skip to main content

Digital Peak and Joomla 3

Still shipping for Joomla 3

Put the DPCalendar 8.x line for Joomla 3 into hybrid maintenance mode in May 2024 and still backports security fixes to it: 8.19.4, 8.19.5 and 8.19.6 all shipped for Joomla 3 in 2026.

Joomla extensions covered: DPCalendar. Digital Peak website

What they said

  • “From now on we put DPCalendar 8.x in hybrid maintenance mode as we still care about our Joomla 3 users.”

    Said 21 May 2024Read it on their siteChecked 2 Oct 2026

What they did

  1. DPCalendar 8.19.4 for Joomla 3 fixes the unauthenticated SQL injection mySites.guru reported

    Source

  2. DPCalendar 8.19.5 for Joomla 3, security fixes only

    Source

  3. DPCalendar 8.19.6 for Joomla 3, security only, fixes the location title escaping mySites.guru reported

    Source

Known Joomla 3 vulnerabilities

  • High

    DPCalendar (com_dpcalendar) 7.0.0 to 8.19.5 (Joomla 3) - Authenticated Stored Cross-Site Scripting

    Affected: ≥ 7.0.0 and < 8.19.6

    CVE-2026-78071

  • Medium

    DPCalendar (com_dpcalendar) 5.5.0 to 8.19.4 (Joomla 3) - Authenticated Blind SQL Injection

    Affected: ≥ 5.5.0 and < 8.19.5

    CVE-2026-78070

  • Medium

    DPCalendar (com_dpcalendar) 9.0.0 to 10.11.2 (Joomla 4 to 6) - Authenticated Blind SQL Injection

    Affected: ≥ 9.0.0 and ≤ 10.11.2

    CVE-2026-78070

  • High

    DPCalendar (com_dpcalendar) 9.0 to 10.11.1 (Joomla 4 to 6) - Unauthenticated Blind SQL Injection

    Affected: ≥ 9.0.0 and < 10.11.2

    CVE-2026-57831

  • High

    DPCalendar (com_dpcalendar) 8.18.0 to 8.19.3 (Joomla 3) - Unauthenticated Blind SQL Injection

    Affected: ≥ 8.18.0 and < 8.19.4

    CVE-2026-57831

Our coverage

See which of your sites run DPCalendar

Connect one site and mySites.guru audits it free, with no card. You see the core vulnerabilities still open on it, the extensions with known holes, and a one-click fix for the core ones.

Keep your Joomla 3 sites patched while you plan the move

One free audit of one site, no card. It shows the core vulnerabilities still open and the extensions with known holes.

Audit a Joomla 3 site free