HarborGuard / CVE
Back to search
CRITICALCVE-2026-21626Published Modified CNA Joomla

CVE-2026-21626: Extension - stackideas.com - Information disclosure in post custom fields in EasyDiscuss 1.0.0-5.0.15 for Joomla

Access control settings for forum post custom fields are not applied to the JSON output type, leading to an ACL violation vector an information disclosure

Metrics

CVSS v4.0
9.2
Severity
CRITICAL
Fixed in
Affected Products
1
Affected packages
  • Stackideas.com / EasyDiscuss extension for Joomla
    1.0.0-5.0.15
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
References