CVE-2026-48906

The vulnerability in the Tassos Framework Plugin allows users to delete arbitrary files on the affected sites.
References
Link Resource
https://tassos.gr Product
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:tassos:advanced_custom_fields:*:*:*:*:*:joomla\!:*:*
cpe:2.3:a:tassos:advanced_custom_fields:*:*:*:*:*:joomla\!:*:*
cpe:2.3:a:tassos:convert_forms:*:*:*:*:*:joomla\!:*:*
cpe:2.3:a:tassos:convert_forms:*:*:*:*:*:joomla\!:*:*
cpe:2.3:a:tassos:engagebox:*:*:*:*:*:joomla\!:*:*
cpe:2.3:a:tassos:engagebox:*:*:*:*:*:joomla\!:*:*
cpe:2.3:a:tassos:google_structured_data:*:*:*:*:*:joomla\!:*:*
cpe:2.3:a:tassos:google_structured_data:*:*:*:*:*:joomla\!:*:*
cpe:2.3:a:tassos:mailchimp_auto-subscribe:*:*:*:*:*:joomla\!:*:*
cpe:2.3:a:tassos:mailchimp_auto-subscribe:*:*:*:*:*:joomla\!:*:*
cpe:2.3:a:tassos:smile_pack:*:*:*:*:*:joomla\!:*:*
cpe:2.3:a:tassos:smile_pack:*:*:*:*:*:joomla\!:*:*
cpe:2.3:a:tassos:tassos_code_snippets:1.0.0:*:*:*:*:joomla\!:*:*
cpe:2.3:a:tassos:tassos_framework:*:*:*:*:*:joomla\!:*:*

History

01 Jun 2026, 14:33

Type Values Removed Values Added
References () https://tassos.gr - () https://tassos.gr - Product
First Time Tassos tassos Code Snippets
Tassos mailchimp Auto-subscribe
Tassos advanced Custom Fields
Tassos engagebox
Tassos tassos Framework
Tassos convert Forms
Tassos smile Pack
Tassos
Tassos google Structured Data
CPE cpe:2.3:a:tassos:mailchimp_auto-subscribe:*:*:*:*:*:joomla\!:*:*
cpe:2.3:a:tassos:tassos_code_snippets:1.0.0:*:*:*:*:joomla\!:*:*
cpe:2.3:a:tassos:tassos_framework:*:*:*:*:*:joomla\!:*:*
cpe:2.3:a:tassos:advanced_custom_fields:*:*:*:*:*:joomla\!:*:*
cpe:2.3:a:tassos:google_structured_data:*:*:*:*:*:joomla\!:*:*
cpe:2.3:a:tassos:smile_pack:*:*:*:*:*:joomla\!:*:*
cpe:2.3:a:tassos:convert_forms:*:*:*:*:*:joomla\!:*:*
cpe:2.3:a:tassos:engagebox:*:*:*:*:*:joomla\!:*:*
CWE NVD-CWE-noinfo
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.1

27 May 2026, 11:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-27 11:16

Updated : 2026-06-01 14:33


NVD link : CVE-2026-48906

Mitre link : CVE-2026-48906

CVE.ORG link : CVE-2026-48906


JSON object : View

Products Affected

tassos

  • convert_forms
  • advanced_custom_fields
  • google_structured_data
  • tassos_framework
  • tassos_code_snippets
  • mailchimp_auto-subscribe
  • smile_pack
  • engagebox
CWE
CWE-284

Improper Access Control

NVD-CWE-noinfo