AJAX Request Handling Flaw in Tassos Framework Plugin for Joomla
CVE-2026-21627
9.5CRITICAL
What is CVE-2026-21627?
The vulnerability in the Tassos Framework plugin arises from a flaw in the handling of AJAX requests via Joomla's com_ajax entry point. This deficiency allows specific internal functionalities of the framework to be executed without appropriate restrictions under certain conditions, potentially exposing the system to unauthorized actions and data manipulation.
Affected Version(s)
Advanced Custom Fields 2.2.0β3.1.0
Convert Forms 3.2.12β5.1.0
EngageBox 6.0.0β7.1.0
