CVE-2026-21627: Tassos.gr Advanced Custom Fields
Critical severity, CVSS 9.5. EPSS: 1.6% chance of exploitation in the next 30 days.
The vulnerability was rooted in how the Tassos Framework plugin handled specific AJAX requests through Joomla’s com_ajax entry point. Under certain conditions, internal framework functionality could be invoked without proper restriction.
Affected products
- Tassos.gr Advanced Custom Fields
- Tassos.gr Convert Forms
- Tassos.gr Engagebox
- Tassos.gr Google Structured Data
- Tassos.gr Novarain/tassos Framework Plg System Nrframework
- Tassos.gr Smile Pack
Published 2026-02-20. Last modified 2026-06-17.