High severity8.1NVD Advisory· Published May 27, 2026· Updated Jun 17, 2026
CVE-2026-48906
CVE-2026-48906
Description
The vulnerability in the Tassos Framework Plugin allows users to delete arbitrary files on the affected sites.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
9- cpe:2.3:a:tassos:advanced_custom_fields:*:*:*:*:*:joomla\!:*:*Range: >=1.0.0,<=2.8.12
- cpe:2.3:a:tassos:google_structured_data:*:*:*:*:*:joomla\!:*:*Range: >=1.0.0,<=5.6.11
- cpe:2.3:a:tassos:mailchimp_auto-subscribe:*:*:*:*:*:joomla\!:*:*Range: >=1.0.0,<=5.0.5
- cpe:2.3:a:tassos:tassos_code_snippets:1.0.0:*:*:*:*:joomla\!:*:*
cpe:2.3:a:tassos:tassos_framework:*:*:*:*:*:joomla\!:*:*+ 1 more
- cpe:2.3:a:tassos:tassos_framework:*:*:*:*:*:joomla\!:*:*range: >=1.0.0,<=6.0.1
- (no CPE)
Patches
Vulnerability mechanics
References
1- tassos.grnvdProduct
News mentions
0No linked articles in our index yet.