
Joomla Extension - https://tassos.gr - Client-controlled validation bypass in Convert Forms extension < 5.2.5 - The front-end Submissions view did not enforce access control. An unauthenticated visitor could therefore list a form's submissions. https://www.cve.org/CVERecord?id=CVE-2026-77026 https://t.co/fovzxjhiA0
Post summary
This note announces a client‑controlled validation bypass in Joomla's Convert Forms extension (CVE‑2026‑77026) that permits unauthenticated listing of form submissions; no PoC, exploit, or patch details are supplied.

