ZeroHour

CVE-2026-48902

CVSS 3.1
9.8 critical
EPSS
<1%p17
Published
()
Modified
Description

The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set.

Vendors
joomla
Products
joomla\!
Weakness
CWE-319
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.