Skip to content
Joomla Novarain/Tassos Framework Vulnerabilities Enable SQL Injection and RCE

Joomla Novarain/Tassos Framework Vulnerabilities Enable SQL Injection and RCE

First seen 16 Feb 2026, 13:09 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 12, 2026 at 16:10 UTC

A source code review of the Novarain/Tassos framework has revealed three critical vulnerabilities: unauthenticated file read, unauthenticated file deletion, and SQL injection. These vulnerabilities affect five widely deployed Joomla! extensions and can be exploited to achieve remote code execution (RCE) and administrator account takeover on unpatched Joomla! instances.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 182d ago How this analysis works

Timeline

2026-02-16
Vulnerabilities disclosed in Joomla! Novarain/Tassos framework
Date unknown
Source code review conducted revealing vulnerabilities

More articles in this cluster (3)