Security
Tassos Framework security patch fixes Joomla AJAX flaw
Tassos has released security updates for six Joomla extensions after a vulnerability in its Tassos Framework system plugin could, under certain conditions, expose server files, remove files, or access Joomla database data through AJAX…
The vulnerability was reported to Greek developer Tassos Marinos on 7 January 2026. It concerns the way the framework handled certain requests through Joomla’s com_ajax entry point, where internal framework functionality could be called without adequate restrictions.
Depending on the conditions, an unauthenticated attacker could read files available to the web server and potentially delete files. Database requests could also be altered in some circumstances to retrieve data from a Joomla database. The combined capabilities could potentially support privilege escalation and unauthorised code execution.
Tassos says there is currently no evidence that the vulnerability has been exploited in real-world conditions. The company conducted an internal code review, added further validation and security measures, and issued corrected versions of the affected extensions.
Fixed extension versions
The following versions contain the security release of the Tassos Framework System Plugin, version 6.0.62:
- Convert Forms:
5.1.1for Joomla 4/5/6,4.1.1for Joomla 3 - EngageBox:
7.1.1for Joomla 4/5/6,6.3.9for Joomla 3 - Google Structured Data:
6.1.1for Joomla 4/5/6,5.6.9for Joomla 3 - Advanced Custom Fields:
3.1.1for Joomla 4/5/6,2.8.10for Joomla 3 - Smile Pack:
2.1.1for Joomla 4/5/6,1.2.4for Joomla 3 - MailChimp Auto-Subscribe:
5.1.1+for Joomla 4/5/6,5.0.4for Joomla 3
Sites with several Tassos extensions need to update only one of them to apply the framework patch, although Tassos recommends updating every installed extension. The company published the security notice on its blog.