Digital Peak and Joomla 3
Put the DPCalendar 8.x line for Joomla 3 into hybrid maintenance mode in May 2024 and still backports security fixes to it: 8.19.4, 8.19.5 and 8.19.6 all shipped for Joomla 3 in 2026.
Joomla extensions covered: DPCalendar. Digital Peak website
What they said
“From now on we put DPCalendar 8.x in hybrid maintenance mode as we still care about our Joomla 3 users.”
Said 21 May 2024Read it on their siteChecked 2 Oct 2026
Known Joomla 3 vulnerabilities
- High
DPCalendar (com_dpcalendar) 7.0.0 to 8.19.5 (Joomla 3) - Authenticated Stored Cross-Site Scripting
Affected: ≥ 7.0.0 and < 8.19.6
- Medium
DPCalendar (com_dpcalendar) 5.5.0 to 8.19.4 (Joomla 3) - Authenticated Blind SQL Injection
Affected: ≥ 5.5.0 and < 8.19.5
- Medium
DPCalendar (com_dpcalendar) 9.0.0 to 10.11.2 (Joomla 4 to 6) - Authenticated Blind SQL Injection
Affected: ≥ 9.0.0 and ≤ 10.11.2
- High
DPCalendar (com_dpcalendar) 9.0 to 10.11.1 (Joomla 4 to 6) - Unauthenticated Blind SQL Injection
Affected: ≥ 9.0.0 and < 10.11.2
- High
DPCalendar (com_dpcalendar) 8.18.0 to 8.19.3 (Joomla 3) - Unauthenticated Blind SQL Injection
Affected: ≥ 8.18.0 and < 8.19.4
Our coverage
- Digital Peak patches four Joomla extensions after a Claude audit
Digital Peak shipped out-of-band fixes for DPCalendar, DPMedia, DPAttachments and DPCases on 10 September. DPAttachments is the one to do first.
- DPCalendar 10.12.0 fixes an SQL injection and an XSS
Digital Peak fixed a blind SQL injection and a stored XSS in DPCalendar 10.12.0, backported to 8.19.5 for Joomla 3. Both need a logged-in user.
- Unauthenticated SQL Injection in DPCalendar found by mySites.guru
mySites.guru found and reported an unauthenticated SQL injection in the DPCalendar Joomla extension's public events feed. Fixed in 10.11.2 and 8.19.4.
See which of your sites run DPCalendar
Connect one site and mySites.guru audits it free, with no card. You see the core vulnerabilities still open on it, the extensions with known holes, and a one-click fix for the core ones.
Keep your Joomla 3 sites patched while you plan the move
One free audit of one site, no card. It shows the core vulnerabilities still open and the extensions with known holes.