CVE-2026-77026: Tassos.gr Convert Forms Extension For Joomla

Medium severity, CVSS 6.9. EPSS: 0.5% chance of exploitation in the next 30 days.

Joomla Extension - tassos.gr - Client-controlled validation bypass in Convert Forms extension < 5.2.5 - The front-end Submissions view did not enforce access control. An unauthenticated visitor could therefore list a form's submissions.

Affected products

  • Tassos.gr Convert Forms Extension For Joomla: version 1.0.0-5.2.5 only

Published 2026-08-20. Last modified 2026-08-26.