CVE WATCH / VULNERABILITY DETAIL
CVE-2026-102780
UNKNOWNCVSS 0NVD feed
Published 5 October 2026 · tracked since 5 October 2026
Description
Joomla Extension - joomlafry.com - Unauthenticated cross-record publication and mass assignment in TF Content 2.9.0 - 2.9.4 - The extension unconditionally authorizes both creation and editing in its public `RecordController`. Its shared frontend save controller accepts the raw `jform` array, assign
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-102779
- CVE-2026-102777
- CVE-2026-102282 HIGH 7.1
- CVE-2026-88396
- CVE-2026-88393
- CVE-2026-105329 MEDIUM 6.3
- CVE-2026-105397 MEDIUM 5.4
- CVE-2026-104890 HIGH 7.2
- CVE-2026-102426
- CVE-2026-102428