Back to overview

CVE-2026-48902

CRITICAL
9.8
CVSS 3.1
Description
The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set.

Metadata

CVE ID
CVE-2026-48902
State
PUBLISHED
Assigner
Joomla
Reserved
2026-05-26 10:06 UTC
Published
2026-05-26 16:43 UTC
Last updated
2026-06-05 07:28 UTC
Primary CWE
CWE-319
CWE-319 Cleartext Transmission of Sensitive Information
Vendor / Product
Joomla! Project / Joomla! CMS
Sources
cve.org  ·  NVD

Severity & Metrics

9.8 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
Joomla! Project Joomla! CMS 3.9.0-5.4.5, 6.0.0-6.1.0
Weakness (CWE)
CWESourceDescription
CWE-319 adp CWE-319 Cleartext Transmission of Sensitive Information
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.8 CRITICAL 3.1 adp CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Back to overview