Joomla Novarain/Tassos Framework Vulnerabilities Enable SQL Injection and RCE

Joomla Novarain/Tassos Framework Vulnerabilities Enable SQL Injection and RCE

First seen 16 Feb 2026, 13:09 UTC RedditGbhackersCybersecuritynews 84% similarity 38.9

Article Content

Browse articles
ThreatCluster

A source code review of the Novarain/Tassos framework has revealed three critical vulnerabilities: unauthenticated file read, unauthenticated file deletion, and SQL injection. These vulnerabilities affect five widely deployed Joomla! extensions and can be exploited to achieve remote code execution (RCE) and administrator account takeover on unpatched Joomla! instances.

ThreatCluster AI

Timeline

2026-02-16
Vulnerabilities disclosed in Joomla! Novarain/Tassos framework
Date unknown
Source code review conducted revealing vulnerabilities

Community

Browse all →

Tracked Entities in This Story