TF Content
Affected versions: ≥ 2.9.0 and < 2.9.5
Full advisory: www.cve.org
TF Content by Joomla Fry, versions 2.9.0 to 2.9.4, contains two unauthenticated missing-authorisation flaws, both fixed in 2.9.5. 1) CVE-2026-102779 (CWE-862, CVSS 4.0 6.9 Medium): the site task records.custom_action is exposed without authentication, ACL, CSRF, task-trigger, content-binding or cron-token checks, so an unauthenticated visitor can supply the numeric ID of any published TF Content task and force the component to run its configured executor immediately. 2) CVE-2026-102780 (CVSS 4.0 6.9 Medium): the public RecordController unconditionally authorises both creating and editing records, and the shared front-end save controller saves the raw jform array against a request-selected record ID without filtering it through the configured form. A guest can take a valid token from Joomla's public login form and modify any TF Content record, including mass-assigning its published state, access level and author (created_by). Update to TF Content 2.9.5 or later. Temporary mitigation: unpublish any TF Content automation tasks whose executors should not be triggered on demand, and disable the TF Content front-end record forms until you can update.
The base metrics as Joomla CNA published them, and what each one means for a site running an affected version. Threat and environmental metrics are left out: they describe a moment or a particular install rather than the flaw.
6.9 Medium
CVSS 4.0, scored by Joomla CNACVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:NTF Content
Affected versions: ≥ 2.9.0 and < 2.9.5
Full advisory: www.cve.org
Updating for CVE-2026-102780 alone can leave a site on a release another rule still matches. These are the other flaws we check for in the same extension.
Latest safe version: 2.9.5
A free audit tells you which of your Joomla and WordPress sites run an affected version, which are out of date, and which have not been backed up. No card required. If a site is already compromised, fix.mysites.guru is a single fixed fee per incident, usually resolved the same day.
This check is part of the mySites.guru Joomla vulnerability scanner, which reads every installed extension's version on each audit. Browse the rest of the Joomla vulnerability database.
Rules current as of 8 October 2026.