CVE-2026-48902
Joomla! Core - [20260518] - Transport encryption downgrade for password and username reset links
criticalEPSS 0.3%
Affected
- bitnami/joomla
3.0.0..* - bitnami/joomla
6.0.0..*
Description
The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set.
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
bitnamijoomla
3.0.06.0.0Metrics
Show all metrics
Severity
critical
72.51
no public PoC known
9.8
Published
2026-05-29 08:44 UTC