VYPR

TF Content

by Joomla

CVEs (1)

  • CVE-2026-102780MedOct 5, 2026
    risk 0.45cvss —epss —

    Joomla Extension - joomlafry.com - Unauthenticated cross-record publication and mass assignment in TF Content 2.9.0 - 2.9.4 - The extension unconditionally authorizes both creation and editing in its public `RecordController`. Its shared frontend save controller accepts the raw…