CVE-2026-21627

Vulnérabilités

CVE-2026-21627

The vulnerability was rooted in how the Tassos Framework plugin handled specific AJAX requests through Joomla’s com_ajax entry point.

CRITICAL com_ajax Composant Source officielle

The vulnerability was rooted in how the Tassos Framework plugin handled specific AJAX requests through Joomla’s com_ajax entry point. Under certain conditions, internal framework functionality could be invoked without proper restriction.

9.5 Critique · CVSS 4.0

CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Score retenu : NVD

SourceSévérité d'origineCVSS
NVDCRITICAL 9.5 (v4.0)
Produit
com_ajax
Type
Composant
Corrigée dans
Non précisée
Publiée
20/02/2026
Modifiée
17/06/2026
CWE
CWE-284
  • Novarain/Tassos Framework (plg_system_nrframework) — 4.10.14 – 6.0.37
  • Convert Forms — 3.2.12 – 5.1.0
  • EngageBox — 6.0.0 – 7.1.0
  • Google Structured Data — 5.1.7 – 6.1.0
  • Advanced Custom Fields — 2.2.0 – 3.1.0
  • Smile Pack — 1.0.0 – 2.1.0

Ces informations proviennent des sources ci-dessus ; CVE Oyer n'y ajoute aucune interprétation.

  1. Détectée via nvd26/09/2026 09:34 UTC