What the vulnerability does
01Description
Joomla Extension - tassos.gr - Sensitive data exposure in Convert Forms extension 2.5.0-5.2.2 - The front-end Submissions view did not enforce access control. An unauthenticated visitor could therefore list a form's submissions.
Explanation of Vulnerability in Simple Terms
02Summary
The Convert Forms extension for Joomla contains an access control flaw that allows attackers to read or modify sensitive data without proper authorization. The vulnerability requires specific attack conditions but can be exploited over the network without authentication. Site administrators should update to a patched version as soon as it becomes available.
What an attacker can do
03Attacker Capabilities
Read or modify sensitive form data and configuration without authorization.
Potential impact on your site
04Site Impact
Attackers could access or alter form submissions, user data, or extension settings on your Joomla site.
Conditions required to exploit
05Prerequisites
Network access; specific attack conditions must be met (high complexity).
Key dates
06Disclosure timeline
July 23, 2026
CVE published
July 24, 2026
Record updated