Junglewise Threat Intelligence

CVE-2026-65758: Tassos Convert Forms for Joomla improper access control in Submissions view

CVE-2026-65758 · Severity: info · CVSS 0 · Published 2026-07-23

Executive brief

A vulnerability exists in Convert Forms, a popular form-building extension for Joomla websites. Due to a lack of access controls in the front-end submissions view, unauthorized visitors could view data submitted through website forms. This could lead to the exposure of sensitive user information, such as contact details or other private data provided by site visitors.

Technical details

An improper access control vulnerability (CWE-284) exists in the front-end Submissions view of the Tassos Convert Forms extension for Joomla. The component fails to verify authorization before displaying submitted form data. An unauthenticated remote attacker can exploit this by accessing the specific front-end view to list and read all submissions associated with a form. The vulnerability affects versions 2.5.0 through 5.2.2. Users should update to a patched version to ensure submission data is restricted to authorized users only.

Affected products

  • tassos.gr Convert Forms extension for Joomla 2.5.0-5.2.2

Timeline

  • 2026-07-23: advisory: NVD publication date

References