CVE Feed

    Dashboard / CVE / CVE-2026-21627

    CVE-2026-21627

    The vulnerability was rooted in how the Tassos Framework plugin handled specific AJAX requests through Joomla’s com_ajax entry point. Under certain conditions, internal framework functionality could be invoked without proper restriction.

    Published:Feb 20, 2026
    Last Modified:Apr 17, 2026
    EPS:Feb 20, 2026
    EPSS Score:0.00018
    CVSS Score:9.5

    Affected Products

    Vendor
    Tassos.gr
    Product
    Advanced Custom Fields
    Vendor
    Tassos.gr
    Product
    Convert Forms
    Vendor
    Tassos.gr
    Product
    Engagebox
    Vendor
    Tassos.gr
    Product
    Google Structured Data
    Vendor
    Tassos.gr
    Product
    Novarain
    Vendor
    Tassos.gr
    Product
    Smile Pack

    Common Weakness Enumeration

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High