CVE-2026-65758 HIGH

CVE-2026-65758: Joomla Extension - tassos.gr - Sensitive data exposure in Convert Forms extension 2.5.0-5.2.2

Vendor Tassos.gr
Product Convert Forms extension for Joomla
Weakness CWE-284
Published July 23, 2026
Last update July 24, 2026

CVSS base score

8.2/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Joomla Extension - tassos.gr - Sensitive data exposure in Convert Forms extension 2.5.0-5.2.2 - The front-end Submissions view did not enforce access control. An unauthenticated visitor could therefore list a form's submissions.

Explanation of Vulnerability in Simple Terms

02Summary

The Convert Forms extension for Joomla contains an access control flaw that allows attackers to read or modify sensitive data without proper authorization. The vulnerability requires specific attack conditions but can be exploited over the network without authentication. Site administrators should update to a patched version as soon as it becomes available.

What an attacker can do

03Attacker Capabilities

Read or modify sensitive form data and configuration without authorization.

Potential impact on your site

04Site Impact

Attackers could access or alter form submissions, user data, or extension settings on your Joomla site.

Conditions required to exploit

05Prerequisites

Network access; specific attack conditions must be met (high complexity).

Key dates

06Disclosure timeline

July 23, 2026 CVE published
July 24, 2026 Record updated

Related vulnerabilities

08Related CVE