CVE-2026-65758 PUBLISHED

Joomla Extension - tassos.gr - Sensitive data exposure in Convert Forms extension 2.5.0-5.2.2

Assigner: Joomla
Reserved: 22.07.2026 Published: 23.07.2026 Updated: 23.07.2026

Joomla Extension - tassos.gr - Sensitive data exposure in Convert Forms extension 2.5.0-5.2.2 - The front-end Submissions view did not enforce access control. An unauthenticated visitor could therefore list a form's submissions.

Product Status

Vendor tassos.gr
Product Convert Forms extension for Joomla
Versions Default: unaffected
  • Version 2.5.0-5.2.2 is affected

Credits

  • Krzysztof Zając, CERT PL finder

References

Problem Types

  • CWE-284 Improper Access Control CWE
  • CWE-200 Exposure of Sensitive Information to an Unauthorized Actor CWE