CVE-2026-48906
Analyzed
Analyzed - Analysis Complete
Arbitrary File Deletion in Tassos Framework Plugin
Publication date: 2026-05-27
Last updated on: 2026-06-01
Assigner: Joomla! Project
Description
Description
The vulnerability in the Tassos Framework Plugin allows users to delete arbitrary files on the affected sites.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| tassos | advanced_custom_fields | From 1.0.0 (inc) to 2.8.12 (inc) |
| tassos | advanced_custom_fields | From 3.0.0 (inc) to 3.1.3 (inc) |
| tassos | convert_forms | From 1.0.0 (inc) to 4.4.12 (inc) |
| tassos | convert_forms | From 5.0.0 (inc) to 5.1.5 (inc) |
| tassos | engagebox | From 1.0.0 (inc) to 6.3.11 (inc) |
| tassos | engagebox | From 7.0.0 (inc) to 7.1.1 (inc) |
| tassos | google_structured_data | From 1.0.0 (inc) to 5.6.11 (inc) |
| tassos | google_structured_data | From 6.0.0 (inc) to 6.1.9 (inc) |
| tassos | mailchimp_auto-subscribe | From 1.0.0 (inc) to 5.0.5 (inc) |
| tassos | mailchimp_auto-subscribe | From 5.1.0 (inc) to 5.2.0 (inc) |
| tassos | smile_pack | From 1.0.0 (inc) to 1.2.6 (inc) |
| tassos | smile_pack | From 2.0.0 (inc) to 2.1.0 (inc) |
| tassos | tassos_code_snippets | 1.0.0 |
| tassos | tassos_framework | From 1.0.0 (inc) to 6.0.1 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-284 | The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor. |