<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>WildforTech Security Advisories — iCagenda</title><description>Actively exploited vulnerabilities affecting iCagenda products.</description><link>https://wildfortech.com</link><atom:link href="https://wildfortech.com/security/vendor/icagenda.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-48939 — iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability</title><link>https://wildfortech.com/security#CVE-2026-48939</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2026-48939</guid><description>iCagenda&apos;s file attachment feature fails to restrict what file types users can upload, allowing attackers to upload PHP files and execute arbitrary code on the server. This is a high-severity vulnerability because remote code execution gives an attacker full control over the affected system — they can steal data, install malware, pivot to internal networks, or establish persistent access. Any internet-facing deployment of iCagenda is at significant risk until this is resolved.</description><pubDate>Fri, 10 Jul 2026 00:00:00 GMT</pubDate><category>iCagenda</category><category>iCagenda</category></item></channel></rss>