9.5
/ 10
CRITICAL
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Description
The vulnerability was rooted in how the Tassos Framework plugin handled specific AJAX requests through Joomla’s com_ajax entry point. Under certain conditions, internal framework functionality could be invoked without proper restriction.
AI Analysis
SQL injection and Unauthenticated File Read vulnerability in Novarain/Tassos Framework for Joomla
Basic Information
ID
CVE-2026-21627
Source
Joomla
Published
Feb 20, 2026 at 14:22
Affected Product
Vendor
tassos.gr
Product
Novarain/Tassos Framework (plg_system_nrframework)
Version
4.10.14–6.0.37
Affected Versions
tassos.gr Novarain/Tassos Framework (plg_system_nrframework) 4.10.14–6.0.37
tassos.gr Convert Forms 3.2.12–5.1.0
tassos.gr EngageBox 6.0.0–7.1.0
tassos.gr Google Structured Data 5.1.7–6.1.0
tassos.gr Advanced Custom Fields 2.2.0–3.1.0
tassos.gr Smile Pack 1.0.0–2.1.0
tassos.gr Convert Forms 3.2.12–5.1.0
tassos.gr EngageBox 6.0.0–7.1.0
tassos.gr Google Structured Data 5.1.7–6.1.0
tassos.gr Advanced Custom Fields 2.2.0–3.1.0
tassos.gr Smile Pack 1.0.0–2.1.0
CWE Classification
AI Assessment
AI Score
9.5 / 10
AI Severity
Critical
Vendor
tassos.gr
Product
Novarain/Tassos Framework
Version
4.10.14–6.0.37