9.3

CVE-2026-48906

Extension - tassos.gr - Arbitrary File Deletion in Novarain/Tassos Framework < 6.1.0 for Joomla

The vulnerability in the Tassos Framework Plugin allows users to delete arbitrary files on the affected sites.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
TassosAdvanced Custom Fields SwPlatformjoomla! Version >= 1.0.0 <= 2.8.12
TassosAdvanced Custom Fields SwPlatformjoomla! Version >= 3.0.0 <= 3.1.3
TassosConvert Forms SwPlatformjoomla! Version >= 1.0.0 <= 4.4.12
TassosConvert Forms SwPlatformjoomla! Version >= 5.0.0 <= 5.1.5
TassosEngagebox SwPlatformjoomla! Version >= 1.0.0 <= 6.3.11
TassosEngagebox SwPlatformjoomla! Version >= 7.0.0 <= 7.1.1
TassosGoogle Structured Data SwPlatformjoomla! Version >= 1.0.0 <= 5.6.11
TassosGoogle Structured Data SwPlatformjoomla! Version >= 6.0.0 <= 6.1.9
TassosMailchimp Auto-subscribe SwPlatformjoomla! Version >= 1.0.0 <= 5.0.5
TassosMailchimp Auto-subscribe SwPlatformjoomla! Version >= 5.1.0 <= 5.2.0
TassosSmile Pack SwPlatformjoomla! Version >= 1.0.0 <= 1.2.6
TassosSmile Pack SwPlatformjoomla! Version >= 2.0.0 <= 2.1.0
TassosTassos Code Snippets Version1.0.0 SwPlatformjoomla!
TassosTassos Framework SwPlatformjoomla! Version >= 1.0.0 <= 6.0.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.27% 0.181
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.1 2.8 5.2
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
security@joomla.org 9.3 0 0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:X/U:X
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.