๐Ÿ” CVE Alert

CVE-2026-102780

UNKNOWN 0.0

Joomla Extension - joomlafry.com - Unauthenticated cross-record publication and mass assignment in TF Content 2.9.0 - 2.9.4

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Joomla Extension - joomlafry.com - Unauthenticated cross-record publication and mass assignment in TF Content 2.9.0 - 2.9.4 - The extension unconditionally authorizes both creation and editing in its public `RecordController`. Its shared frontend save controller accepts the raw `jform` array, assigns the request-selected existing record ID, and saves it without filtering submitted properties through the configured form. A Guest can obtain a valid token from Joomla's public login form and modify any TF Content row, including mass-assigning `published`, `access`, and `created_by`.

CWE CWE-862 CWE-915
Vendor joomlafry.com
Product tf content for joomla
Published Oct 5, 2026
Last Updated Oct 5, 2026
Stay Ahead of the Next One

Get instant alerts for joomlafry.com tf content for joomla

Be the first to know when new unknown vulnerabilities affecting joomlafry.com tf content for joomla are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

joomlafry.com / TF Content for Joomla
2.9.0-2.9.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
joomlafry.com: https://www.joomlafry.com/

Credits

ลukasz Rybak