Sensitive Data Exposure Vulnerability in Convert Forms by Tassos.gr
CVE-2026-65758

8.2HIGH

Key Information:

Vendor

Tassos.gr

Vendor
CVE Published:
23 July 2026

What is CVE-2026-65758?

The Convert Forms extension for Joomla, developed by Tassos.gr, has a vulnerability that allows unauthenticated users to access sensitive form submissions due to insufficient access controls in the front-end Submissions view. This flaw can lead to unauthorized data exposure, posing risks to user privacy and data integrity. It's essential for users of the affected versions (2.5.0-5.2.2) to take immediate steps to secure their installations to prevent potential exploitation.

Affected Version(s)

Convert Forms extension for Joomla 2.5.0-5.2.2

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Krzysztof ZajÄ…c, CERT PL
.