logo

Joomla Vulnerabilities in Novarain/Tassos Framework Expose SQL Injection Risks

ID: 94ca9c2a-3c6c-5063-8442-0c3a5c467cd3

STIX ID: report--94ca9c2a-3c6c-5063-8442-0c3a5c467cd3

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-02-16

Date Updated: 2026-04-22

Author: Divya

...
...

This report describes multiple critical vulnerabilities in the Novarain/Tassos Framework (plg_system_nrframework) used by several Joomla extensions that allow unauthenticated local file reads and deletions, SQL injection for arbitrary database reads, and an AJAX include pattern that can be chained to achieve administrator takeover and reliable remote code execution; affected products and versions are listed, vendor updates are available, and administrators are advised to patch, disable the plugin/extensions, or restrict ?option=com_ajax endpoints.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.