Skip to content
CodeAuditAgent

CVE-2026-48902

The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set.

Weakness

The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set.

Affected products

  • joomla joomla\!

References

Find the bug before an attacker does.

Sign in with GitHub and run your first audit in under a minute. The free plan needs no credit card.