Description
The vulnerability was rooted in how the Tassos Framework plugin handled specific AJAX requests through Joomla’s com_ajax entry point. Under certain conditions, internal framework functionality could be invoked without proper restriction.
Published: 2026-02-20
Score: 9.5 Critical
EPSS: 1.5% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Tassos Framework plugin processes certain AJAX requests through Joomla’s com_ajax entry point without adequate access checks. When an attacker sends a specifically crafted request, internal framework functions can be invoked without authentication. This flaw allows the injection of arbitrary SQL commands and the reading of files that should be protected, giving an attacker direct access to database contents and sensitive configuration files, thereby compromising both confidentiality and integrity.

Affected Systems

Product families that use the Tassos Framework plugin include Advanced Custom Fields, Convert Forms, EngageBox, Google Structured Data, and Smile Pack. No specific version information is disclosed in the CVE entry, so any release of these extensions that includes the vulnerable plugin could be affected.

Risk and Exploitability

The vulnerability carries a CVSS score of 9.5, indicating critical severity. The EPSS score is reported as 2%, which is relatively low but non‑zero, suggesting a modest probability of exploitation in the wild. The flaw is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is remote unauthenticated via crafted AJAX requests to the com_ajax endpoint, exploiting an access‑control weakness (CWE‑284). No local privileges or other prerequisites are required for the attacker to achieve the full impact.

Generated by OpenCVE AI on August 4, 2026 at 08:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check the vendor’s website for updates and apply the latest release of the Tassos Framework plugin and all bundled extensions.
  • Restrict access to Joomla’s com_ajax endpoint by configuring ACLs so that only authenticated users can invoke it, or by blocking unauthenticated requests with a firewall.
  • If a patch is not yet available, disable or uninstall the vulnerable Tassos extensions or the entire Tassos Framework plugin until a fix is released.

Generated by OpenCVE AI on August 4, 2026 at 08:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
Link Providers
https://tassos.gr cve-icon cve-icon
History

Mon, 23 Feb 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Tassos.gr
Tassos.gr advanced Custom Fields
Tassos.gr convert Forms
Tassos.gr engagebox
Tassos.gr google Structured Data
Tassos.gr novarain
Tassos.gr smile Pack
Vendors & Products Tassos.gr
Tassos.gr advanced Custom Fields
Tassos.gr convert Forms
Tassos.gr engagebox
Tassos.gr google Structured Data
Tassos.gr novarain
Tassos.gr smile Pack

Fri, 20 Feb 2026 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 20 Feb 2026 14:30:00 +0000

Type Values Removed Values Added
Description The vulnerability was rooted in how the Tassos Framework plugin handled specific AJAX requests through Joomla’s com_ajax entry point. Under certain conditions, internal framework functionality could be invoked without proper restriction.
Title Extension - tassos.gr - SQL injection and Unauthenticated File Read in Novarain/Tassos Framework v4.10.14 – v6.0.37 for Joomla
Weaknesses CWE-284
References
Metrics cvssV4_0

{'score': 9.5, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

Tassos.gr Advanced Custom Fields Convert Forms Engagebox Google Structured Data Novarain Smile Pack
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-02-23T05:07:12.296Z

Reserved: 2026-01-01T04:42:27.960Z

Link: CVE-2026-21627

cve-icon Vulnrichment

Updated: 2026-02-20T20:43:02.670Z

cve-icon NVD

Status : Deferred

Published: 2026-02-20T15:20:29.467

Modified: 2026-06-17T10:18:50.007

Link: CVE-2026-21627

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T09:00:06Z

Weaknesses