BIT-joomla-2026-48902

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/joomla/BIT-joomla-2026-48902.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-joomla-2026-48902
Aliases
  • CVE-2026-48902
Published
2026-05-29T08:44:46.031Z
Modified
2026-05-29T09:15:04.617110123Z
Summary
Joomla! Core - [20260518] - Transport encryption downgrade for password and username reset links
Details

The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set.

Database specific
{
    "cpes": [
        "cpe:2.3:a:joomla:joomla!:*:*:*:*:*:*:*:*"
    ],
    "severity": "Critical"
}
References

Affected packages

Bitnami / joomla

Package

Name
joomla
Purl
pkg:bitnami/joomla

Severity

  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
3.0.0
Fixed
5.4.6
Introduced
6.0.0
Fixed
6.1.1

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/joomla/BIT-joomla-2026-48902.json"