AJAX Request Handling Flaw in Tassos Framework Plugin for Joomla
CVE-2026-21627

9.5CRITICAL

What is CVE-2026-21627?

The vulnerability in the Tassos Framework plugin arises from a flaw in the handling of AJAX requests via Joomla's com_ajax entry point. This deficiency allows specific internal functionalities of the framework to be executed without appropriate restrictions under certain conditions, potentially exposing the system to unauthorized actions and data manipulation.

Affected Version(s)

Advanced Custom Fields 2.2.0–3.1.0

Convert Forms 3.2.12–5.1.0

EngageBox 6.0.0–7.1.0

References

CVSS V4

Score:
9.5
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

p1r0x / ssd-disclosure.com
.