Executive brief
Convert Forms is a popular contact form builder extension for Joomla websites. The Submissions view—which displays user-submitted form data—did not require authentication, allowing any unauthenticated visitor to access and view all form submissions. This could expose sensitive customer data, inquiries, and application details to unauthorized parties.
Technical details
The vulnerability is an access control bypass (CWE-639) in the front-end Submissions view of Convert Forms. The vulnerable component failed to enforce authentication checks, allowing unauthenticated HTTP requests to retrieve submission records. An attacker can directly access the Submissions view without credentials to enumerate and read all submitted form data, including personal information, contact details, and file uploads. The vulnerability was resolved in version 5.2.5 and later.
Affected products
- Tassos.gr Convert Forms < 5.2.5
Timeline
- 2026-08-20: disclosed