CVE-2026-48902

EUVD-2026-31878
The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 16.29%
Affected Products (NVD)
VendorProductVersion
joomlajoomla\!
3.0.0 ≤
𝑥
< 5.4.6
joomlajoomla\!
6.0.0 ≤
𝑥
< 6.1.1
𝑥
= Vulnerable software versions