SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-77026

MEDIUM · CVSS 6.9 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-08-20 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The Convert Forms extension for Joomla versions prior to 5.2.5 is vulnerable due to a client-controlled validation bypass, allowing unauthenticated users to access and list form submissions without proper access control. This exposure could lead to unauthorized data disclosure, impacting the confidentiality of user-submitted information. Joomla administrators using this extension should prioritize applying the latest updates to mitigate potential data breaches.

CVE
CVE-2026-77026
Severity
MEDIUM
CVSS
6.9
EPSS
0.27%

Original NVD Description

Joomla Extension - tassos.gr - Client-controlled validation bypass in Convert Forms extension < 5.2.5 - The front-end Submissions view did not enforce access control. An unauthenticated visitor could therefore list a form's submissions.