yallasec

2 exploits Active since Feb 2026
CVE-2026-21627 GITHUB CRITICAL python WORKING POC
Tassos Framework Plugin - Auth Bypass
The vulnerability was rooted in how the Tassos Framework plugin handled specific AJAX requests through Joomla’s com_ajax entry point. Under certain conditions, internal framework functionality could be invoked without proper restriction.
10 stars
CVE-2026-21627 NOMISEC CRITICAL WORKING POC
Tassos Framework Plugin - Auth Bypass
The vulnerability was rooted in how the Tassos Framework plugin handled specific AJAX requests through Joomla’s com_ajax entry point. Under certain conditions, internal framework functionality could be invoked without proper restriction.