CVE-2026-78074

Joomla Extension - miniorgange.com - Unauthenticated arbitrary extension deinstallation via various miniOrange extensions - a missing authentication check allows unauthenticated actors to delete arbitrary installed extensions. Only the free versions of the miniOrange plugins are affected.
CVSS

No CVSS.

References
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-31 14:17

Updated : 2026-09-08 11:17


NVD link : CVE-2026-78074

Mitre link : CVE-2026-78074

CVE.ORG link : CVE-2026-78074


JSON object : View

Products Affected

No product.

CWE
CWE-284

Improper Access Control