CVE-2026-48902

CRITICAL9.8EPSS 0.00%

Joomla! Core - [20260518] - Transport encryption downgrade for password and username reset links

Published: 5/29/2026Modified: 5/29/2026

Description

The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1CRITICAL9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References (2)