CVE-2026-77026
Received Received - Intake

Client-Controlled Validation Bypass in Convert Forms Joomla Extension

Vulnerability report for CVE-2026-77026, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-20

Last updated on: 2026-08-20

Assigner: Joomla! Project

Description

Joomla Extension - tassos.gr - Client-controlled validation bypass in Convert Forms extension < 5.2.5 - The front-end Submissions view did not enforce access control. An unauthenticated visitor could therefore list a form's submissions.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-20
Last Modified
2026-08-20
Generated
2026-08-20
AI Q&A
2026-08-20
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
tassos_gr convert_forms to 5.2.5 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-602 The product is composed of a server that relies on the client to implement a mechanism that is intended to protect the server.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a client-controlled validation bypass in the Convert Forms Joomla extension version 5.2.5 or earlier. It allows unauthenticated visitors to bypass access controls and list form submissions through the front-end Submissions view.

Detection Guidance

Check if the Convert Forms extension version is below 5.2.5 by inspecting the Joomla admin panel or running a server-side command like 'find /path/to/joomla -name "com_convertforms" -type d' to locate the extension directory and verify its version.

Impact Analysis

An attacker could exploit this to access sensitive form submissions without authentication. This may lead to data leaks, privacy violations, or unauthorized access to user-provided information like contact details, payment data, or survey responses.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR (data protection) and HIPAA (health information privacy) by exposing personal or sensitive data. Organizations may face legal penalties, fines, or reputational damage if user data is compromised through this flaw.

Mitigation Strategies

Update the Convert Forms extension to version 5.2.5 or later immediately. Disable unauthenticated access to the front-end Submissions view if possible. Review server logs for suspicious activity related to form submissions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-77026. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart