Tassos and Joomla 3
Points Joomla 3 sites to a legacy release built for Joomla 3.x, and still patches that branch: Convert Forms 4.4.16 and 4.4.17 shipped security fixes for Joomla 3 in July and August 2026.
Joomla extensions covered: Convert Forms, Engage. Tassos website
What they said
“To install on a Joomla 3 website you must download and install a legacy release built for Joomla 3.x.”
UndatedRead it on their siteChecked 2 Oct 2026
Known Joomla 3 vulnerabilities
- High
Convert Forms (com_convertforms) 4.4.10 to 4.4.15 (Joomla 3 branch) - Unauthenticated Submission Disclosure
Affected: ≥ 4.4.10 and < 4.4.16
- Unrated
Convert Forms (com_convertforms) 5.0.0 to 5.2.2 (Joomla 4/5/6 branch) - Unauthenticated Submission Disclosure
Affected: ≥ 5.0.0 and ≤ 5.2.2
- Unrated
Convert Forms (com_convertforms) 5.2.3 to 5.2.4 (Joomla 4/5/6 branch) - Unauthenticated Client-Controlled Validation Bypass (CAPTCHA and field validation bypass, CVE-2026-77026)
Affected: ≥ 5.2.3 and < 5.2.5
- Unrated
Convert Forms (com_convertforms) 4.4.16 (Joomla 3 branch) - Unauthenticated Client-Controlled Validation Bypass (CAPTCHA and field validation bypass, CVE-2026-77026)
Affected: ≥ 4.4.16 and < 4.4.17
Our coverage
- Novarain Framework Vulnerability: Check Your Joomla Sites for nrframework
CVE-2026-21627 (CVSS 9.5) - Tassos/Novarain Framework for Joomla allows unauthenticated file inclusion, deletion, and SQL injection.
See which of your sites run Convert Forms
Connect one site and mySites.guru audits it free, with no card. You see the core vulnerabilities still open on it, the extensions with known holes, and a one-click fix for the core ones.
Keep your Joomla 3 sites patched while you plan the move
One free audit of one site, no card. It shows the core vulnerabilities still open and the extensions with known holes.