HTProtect.org
Independent information site on Joomla security vulnerabilities
HTProtect HTProtect JOOMLA SECURITY
htprotect.org Vulnerabilities & update guides
Security vulnerability

Tassos Framework (formerly Novarain) – critical flaw, CVSS 9.5

CriticalCVSS 9.5 / 10Public exploit availableCVE-2026-21627
Act now
Update any Tassos extension – this automatically raises the framework to 6.0.62+.

Secure version: Tassos Framework 6.0.62 or higher · via Tassos account

At a glance

Affected extension
Tassos Framework (formerly Novarain) – system plugin plg_system_nrframework
Type of flaw
Unauthenticated AJAX calls via com_ajax allow file and database access; a public exploit tool is available
Affected versions
Framework versions 4.10.14 to 6.0.37
Secure version
Tassos Framework 6.0.62 or higher   Download
Severity
Critical · CVSS 9.5 / 10
Joomla compatibility
Joomla 3 / 4 / 5 / 6
Status / published
As of: 4 April 2026

What is this about?

The Tassos Framework – formerly known as the Novarain Framework – runs as a system plugin (plg_system_nrframework) and forms the shared basis of several popular extensions. Via com_ajax, AJAX requests were possible without authentication, allowing file access, file deletion and database access, among other things.

The flaw (CVE-2026-21627) is rated critical with a CVSS score of 9.5 out of 10; a public exploit tool is available. Vulnerable are framework versions 4.10.14 to 6.0.37.

Affected in particular are the following extensions: Convert Forms, EngageBox, Google Structured Data, Advanced Custom Fields, Smile Pack and MailChimp Auto-Subscribe. Since they all use the same framework base, it is enough to update one of them – the framework is updated along with it.

Secure minimum versions per extension

ExtensionJoomla 4 / 5 / 6Joomla 3
Convert Forms5.1.14.4.11
EngageBox7.1.16.3.9
Google Structured Data6.1.15.6.9
Advanced Custom Fields3.1.12.8.10
Smile Pack2.1.11.2.4
MailChimp Auto-Subscribe5.1.15.0.4

After updating one of these extensions, the Tassos Framework must show 6.0.62 or higher.

Am I affected? – How to check

  1. Open the back end

    Log in to the Joomla administrator.

  2. Check the framework

    Open SystemPlugins and search for Tassos Framework. Alternatively, check the files /plugins/system/nrframework/nrframework.php and nrframework.xml.

  3. Assess the version

    If the framework version is between 4.10.14 and 6.0.37, the site is vulnerable. Secure is 6.0.62 or higher.

How to fix it

Before any update: back up
Back up your files and database before updating – so you can roll back if anything goes wrong (e.g. via Akeeba Backup or your host).
  1. Open the Update center

    Go to SystemUpdateExtensions and click Check for updates.

  2. Update one Tassos extension

    Update any installed Tassos extension (see table) to the stated minimum version. The framework is updated along with it.

  3. Verify the framework

    Check under SystemPlugins that "Tassos Framework" now shows 6.0.62 or higher.

Official source: via Tassos account. Make sure you have at least Tassos Framework 6.0.62 or higher.

Has the site already been attacked?

The framework often stays active unnoticed
It runs in the background and can remain even after uninstalling an extension (it is not removed automatically). Attacks are possible without login. If you suspect a compromised site, also check for: backdoors, suspicious administrator accounts and tampered files.

Sources & further reading

The official information from the respective vendor always takes precedence. This page neutrally summarises publicly available information.

Supporters

Supporters of this site

htprotect.org is a free, vendor-independent information service. It is supported by:

Host & community
FC-Hosting

Joomla host from Germany with active community support – discovered the first attack on the JCE vulnerability.

fc-hosting.de
Initiator & operator
Website-Bereinigung.de

Specialised in cleaning, maintaining and securing Joomla and WordPress websites.

website-bereinigung.de

Support this project

You run a hosting or Joomla service and would like to support htprotect.org – and be listed here as a supporter? Every contribution helps to warn and protect those affected faster.

Support HTProtect now