No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 28 May 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-200 |
Thu, 28 May 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Joomla joomla\!
|
|
| Weaknesses | CWE-200 NVD-CWE-noinfo |
|
| CPEs | cpe:2.3:a:joomla:joomla\!:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Joomla joomla\!
|
Thu, 28 May 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-319 CWE-640 |
Thu, 28 May 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 27 May 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Joomla
Joomla joomla! |
|
| Vendors & Products |
Joomla
Joomla joomla! |
Tue, 26 May 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-319 CWE-640 |
Tue, 26 May 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set. | |
| Title | Joomla! Core - [20260518] - Transport encryption downgrade for password and username reset links | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Joomla
Published:
Updated: 2026-05-28T13:23:59.048Z
Reserved: 2026-05-26T10:06:17.656Z
Link: CVE-2026-48902
Updated: 2026-05-28T13:23:27.192Z
Status : Analyzed
Published: 2026-05-26T17:16:54.970
Modified: 2026-05-28T19:28:49.850
Link: CVE-2026-48902
No data.
OpenCVE Enrichment
Updated: 2026-05-28T22:30:28Z