9.3
/ 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H/AU:Y
Description
The vulnerability in the Tassos Framework Plugin allows users to delete arbitrary files on the affected sites.
AI Analysis
Arbitrary file deletion vulnerability in Novarain/Tassos Framework Plugin
Basic Information
ID
CVE-2026-48906
Source
Joomla
Published
May 27, 2026 at 09:11
Affected Product
Vendor
tassos.gr
Product
Novarain/Tassos Framework (plg_system_nrframework)
Version
1.0.0-6.0.1
Affected Versions
tassos.gr Novarain/Tassos Framework (plg_system_nrframework) 1.0.0-6.0.1
tassos.gr Convert Forms 1.0.0-4.4.12
tassos.gr Convert Forms 5.0.0-5.1.5
tassos.gr EngageBox 1.0.0-6.3.11
tassos.gr EngageBox 7.0.0-7.1.1
tassos.gr Google Structured Data 1.0.0-5.6.11
tassos.gr Google Structured Data 6.0.0-6.1.9
tassos.gr Advanced Custom Fields 1.0.0-2.8.12
tassos.gr Advanced Custom Fields 3.0.0-3.1.3
tassos.gr Smile Pack 1.0.0-1.2.6
tassos.gr Smile Pack 2.0.0-2.1.0
tassos.gr Tassos Code Snippets 1.0.0
tassos.gr MailChimp Auto-Subscribe 1.0.0-5.0.5
tassos.gr MailChimp Auto-Subscribe 5.1.0-5.2.0
tassos.gr Convert Forms 1.0.0-4.4.12
tassos.gr Convert Forms 5.0.0-5.1.5
tassos.gr EngageBox 1.0.0-6.3.11
tassos.gr EngageBox 7.0.0-7.1.1
tassos.gr Google Structured Data 1.0.0-5.6.11
tassos.gr Google Structured Data 6.0.0-6.1.9
tassos.gr Advanced Custom Fields 1.0.0-2.8.12
tassos.gr Advanced Custom Fields 3.0.0-3.1.3
tassos.gr Smile Pack 1.0.0-1.2.6
tassos.gr Smile Pack 2.0.0-2.1.0
tassos.gr Tassos Code Snippets 1.0.0
tassos.gr MailChimp Auto-Subscribe 1.0.0-5.0.5
tassos.gr MailChimp Auto-Subscribe 5.1.0-5.2.0
CWE Classification
AI Assessment
AI Score
9.3 / 10
AI Severity
Critical
Vendor
tassos.gr
Product
Novarain/Tassos Framework
Version
1.0.0-6.0.1