CVE 9.3 CRITICAL

Extension – tassos.gr – Arbitrary File Deletion in Novarain/Tassos Framework < 6.1.0 for Joomla_CVE-2026-48906

9.3 / 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H/AU:Y

Description

The vulnerability in the Tassos Framework Plugin allows users to delete arbitrary files on the affected sites.

AI Analysis

Arbitrary file deletion vulnerability in Novarain/Tassos Framework Plugin

Basic Information

ID CVE-2026-48906
Source Joomla
Published May 27, 2026 at 09:11

Affected Product

Vendor tassos.gr
Product Novarain/Tassos Framework (plg_system_nrframework)
Version 1.0.0-6.0.1
Affected Versions tassos.gr Novarain/Tassos Framework (plg_system_nrframework) 1.0.0-6.0.1
tassos.gr Convert Forms 1.0.0-4.4.12
tassos.gr Convert Forms 5.0.0-5.1.5
tassos.gr EngageBox 1.0.0-6.3.11
tassos.gr EngageBox 7.0.0-7.1.1
tassos.gr Google Structured Data 1.0.0-5.6.11
tassos.gr Google Structured Data 6.0.0-6.1.9
tassos.gr Advanced Custom Fields 1.0.0-2.8.12
tassos.gr Advanced Custom Fields 3.0.0-3.1.3
tassos.gr Smile Pack 1.0.0-1.2.6
tassos.gr Smile Pack 2.0.0-2.1.0
tassos.gr Tassos Code Snippets 1.0.0
tassos.gr MailChimp Auto-Subscribe 1.0.0-5.0.5
tassos.gr MailChimp Auto-Subscribe 5.1.0-5.2.0

CWE Classification

AI Assessment

AI Score 9.3 / 10
AI Severity Critical
Vendor tassos.gr
Product Novarain/Tassos Framework
Version 1.0.0-6.0.1

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.