CVE-2026-77026: Joomla Extension - tassos.gr - Client-controlled validation bypass in Convert Forms extension < 5.2.5
Published Aug 20, 2026
·Updated
Joomla Extension - tassos.gr - Client-controlled validation bypass in Convert Forms extension < 5.2.5 - The front-end Submissions view did not enforce access control. An unauthenticated visitor could therefore list a form's submissions.
Affected Software
1 affected component
Joomla extension/tassos.gr - Convert Forms<5.2.5
Event History
Aug 20, 2026
CVE Published
via MITRE·10:35 AM
Data Sourced
via MITRE·10:35 AM
DescriptionWeakness
Frequently Asked Questions
1
Who can exploit this issue?
Any unauthenticated visitor can exploit it if the affected front-end Submissions view is accessible. No login is required.
2
What information could be exposed?
An attacker could list the submissions for a form through the front-end Submissions view. The provided information does not specify which submission fields or forms are exposed.
3
Which installations are affected?
Convert Forms versions earlier than 5.2.5 are affected. The issue is in the front-end Submissions view, which did not enforce access control.