Security
Critical Novarain Framework flaw puts Joomla sites at risk
A critical vulnerability in the Tassos/Novarain Framework for Joomla allows unauthenticated attackers to include, read and delete files and carry out SQL injection.
Research published by mySites.guru identifies the issue as CVE-2026-21627, with a CVSS score of 9.5. It affects the plg_system_nrframework plugin in versions 4.10.14 through 6.0.37. Tassos.gr fixed the issue in version 6.0.38 and later releases.
The framework is commonly installed as a dependency of Tassos extensions, including:
Convert FormsEngageBoxGoogle Structured DataAdvanced Custom FieldsSmile Pack
The vulnerability is reachable without authentication through Joomla’s AJAX endpoint. A public exploit tool with multiple attack modes is available on GitHub. Tassos.gr said in its 18 February advisory that it had no evidence of exploitation in the wild at that time.
Administrators should check whether plg_system_nrframework is installed, update it to 6.0.38 or newer through Tassos.gr, and review affected sites for signs of compromise if they were running a vulnerable release.
Originally reported by mySites.guru.