CVE-2026-102780
Joomla Extension - joomlafry.com - Unauthenticated cross-record publication and mass assignment in TF Content 2.9.0 - 2.9.4
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Joomla Extension - joomlafry.com - Unauthenticated cross-record publication and mass assignment in TF Content 2.9.0 - 2.9.4 - The extension unconditionally authorizes both creation and editing in its public `RecordController`. Its shared frontend save controller accepts the raw `jform` array, assigns the request-selected existing record ID, and saves it without filtering submitted properties through the configured form. A Guest can obtain a valid token from Joomla's public login form and modify any TF Content row, including mass-assigning `published`, `access`, and `created_by`.
| CWE | CWE-862 CWE-915 |
| Vendor | joomlafry.com |
| Product | tf content for joomla |
| Published | Oct 5, 2026 |
| Last Updated | Oct 5, 2026 |
Stay Ahead of the Next One
Get instant alerts for joomlafry.com tf content for joomla
Be the first to know when new unknown vulnerabilities affecting joomlafry.com tf content for joomla are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
joomlafry.com / TF Content for Joomla
2.9.0-2.9.4
Credits
ลukasz Rybak