Gbhackers
Joomla Novarain/Tassos Framework Vulnerabilities Enable SQL Injection and RCE
First seen 16 Feb 2026, 13:09 UTC
•

•84% similarity
•38.9
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
A source code review of the Novarain/Tassos framework has revealed three critical vulnerabilities: unauthenticated file read, unauthenticated file deletion, and SQL injection. These vulnerabilities affect five widely deployed Joomla! extensions and can be exploited to achieve remote code execution (RCE) and administrator account takeover on unpatched Joomla! instances.
ThreatCluster AI
Timeline
2026-02-16
Vulnerabilities disclosed in Joomla! Novarain/Tassos framework
Date unknown
Source code review conducted revealing vulnerabilities