Skip to main content
mySites.guru
J!Awards 2026mySites.guru is shortlisted for Your Favourite Tool in Your Joomla WorkflowVote by 11 OctoberHow to vote
CVE-2026-102780MediumCVSS 6.9CVE published 5 October 2026Added to mySites.guru 5 October 2026

TF Content (com_tfcontent) 2.9.0 to 2.9.4 - Unauthenticated Forced Execution of Automation Tasks and Record Tampering (Missing Authorisation)

TF Content by Joomla Fry, versions 2.9.0 to 2.9.4, contains two unauthenticated missing-authorisation flaws, both fixed in 2.9.5. 1) CVE-2026-102779 (CWE-862, CVSS 4.0 6.9 Medium): the site task records.custom_action is exposed without authentication, ACL, CSRF, task-trigger, content-binding or cron-token checks, so an unauthenticated visitor can supply the numeric ID of any published TF Content task and force the component to run its configured executor immediately. 2) CVE-2026-102780 (CVSS 4.0 6.9 Medium): the public RecordController unconditionally authorises both creating and editing records, and the shared front-end save controller saves the raw jform array against a request-selected record ID without filtering it through the configured form. A guest can take a valid token from Joomla's public login form and modify any TF Content record, including mass-assigning its published state, access level and author (created_by). Update to TF Content 2.9.5 or later. Temporary mitigation: unpublish any TF Content automation tasks whose executors should not be triggered on demand, and disable the TF Content front-end record forms until you can update.

Is my site affected?

Affected
TF Content from 2.9.0 up to but not including 2.9.5
Fixed in
2.9.5
What to do
Update TF Content to 2.9.5 or later.

How CVE-2026-102780 is scored

The base metrics as Joomla CNA published them, and what each one means for a site running an affected version. Threat and environmental metrics are left out: they describe a moment or a particular install rather than the flaw.

6.9 Medium

CVSS 4.0, scored by Joomla CNA
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

How it is reached

AV:N Attack vector
Network. Reachable across the internet
AC:L Attack complexity
Low. Nothing to work around, it just works
AT:N Attack requirements
None. Works against any affected install
PR:N Privileges required
None. No account needed
UI:N User interaction
None. Nobody has to be tricked into anything

What it does to the site

VC:L Confidentiality
Low. Some data can be read
VI:L Integrity
Low. Some data can be altered
VA:L Availability
Low. The site slows or stutters

What it does beyond the site

SC:N Confidentiality
None. Other systems keep their data
SI:N Integrity
None. Other systems keep their integrity
SA:N Availability
None. Other systems stay up

Timeline

  1. 5 October 2026CVE-2026-102780 record published by its CNA
  2. 5 October 2026mySites.guru check added for TF Content (from 2.9.0 up to but not including 2.9.5)

Rule details

Other vulnerabilities in TF Content

Updating for CVE-2026-102780 alone can leave a site on a release another rule still matches. These are the other flaws we check for in the same extension.

TF Content

Latest safe version: 2.9.5

References

CVE-2026-102780 questions

Which versions are affected by CVE-2026-102780?
CVE-2026-102780 affects TF Content from 2.9.0 up to but not including 2.9.5. The fix is in 2.9.5.
How do I fix CVE-2026-102780?
Update TF Content to 2.9.5 or later. Then confirm the installed version on the Joomla administrator's Extensions: Manage screen.
How severe is CVE-2026-102780?
Joomla CNA scores it 6.9 (Medium) under CVSS 4.0. In plain terms: reachable across the internet, no account needed and nobody has to be tricked into anything.

Running an affected version on a site you manage?

A free audit tells you which of your Joomla and WordPress sites run an affected version, which are out of date, and which have not been backed up. No card required. If a site is already compromised, fix.mysites.guru is a single fixed fee per incident, usually resolved the same day.

This check is part of the mySites.guru Joomla vulnerability scanner, which reads every installed extension's version on each audit. Browse the rest of the Joomla vulnerability database.

Rules current as of 8 October 2026.