Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
The Structured Data Company

The Structured Data Company Vendor Cyber Rating & Cyber Score

structureddata.co.uk

The Structured Data Company was founded in Kent, UK on 22nd November 2024 by Kelly Sheppard and is one of the only dedicated consultancies for schema markup in the UK. Specialising in bespoke, handwritten structured data markup, The Structured Data Company helps businesses improve their online visibility and drive organic traffic through entity-based structured data strategies. Why Choose The Structured Data Company? We Prioritise Your Goals We are committed to delivering tailored solutions to meet your specific business’ needs and will prioritise your business goals over our own. Committed To Transparency We're a no-nonsense consultancy, committed to transparency and integrity. Honest and Straightfoward Advice We'll focus on


SDC A.I CyberSecurity Scoring

SDC
Company Information
Website:https://www.structureddata.co.uk/
Employees number:1
Number of followers:34
NAICS:5418
Industry Type:Marketing Services
Homepage:structureddata.co.uk
SDC Risk Score (AI oriented)
Between 700 and 749
logo
SDCMarketing Services
Updated:
12/03/2026
749/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
SDC Global Score (TPRM)
xxxx
logo
SDCMarketing Services
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

SDC
SDCModerate
Current Score
749Ba (MODERATE)
01000
1 incidents
-1 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
750Before Incident
MAY 2026
749Before Incident
APRIL 2026
749Before Incident
MARCH 2026
749Before Incident
FEBRUARY 2026
750Before Incident
Vulnerability
16 Feb 2026SDC
EngageBox, Tassos, Google Structured Data and Convert Forms: Critical Joomla Novarain/Tassos Framework Flaws Enable SQL Injection and Unauthenticated File Read

Critical Joomla Framework Vulnerabilities Expose Sites to RCE and Data Theft

749After Incident
CRITICAL-1
TASTHE1771259547
Critical Joomla Framework Vulnerabilities Expose Sites to RCE and Data Theft Independent researcher p1r0x, in collaboration with SSD Secure Disclosure, has uncovered severe vulnerabilities in Joomla extensions relying on the Novarain/Tassos Framework (now rebranded as Tassos Framework). The flaws enable SQL injection, unauthenticated file reads, and file deletions, which attackers can chain to achieve administrator account takeover and remote code execution (RCE) on unpatched systems. ### Affected Extensions and Framework The vulnerabilities impact multiple popular Joomla extensions that depend on the plg_system_nrframework plugin, including: - Convert Forms (v3.2.12 – v5.1.0) - EngageBox (v6.0.0 – v7.1.0) - Google Structured Data (v5.1.7 – v6.1.0) - Advanced Custom Fields (v2.2.0 – v3.1.0) - Smile Pack (v1.0.0 – v2.1.0) - Novarain/Tassos Framework (v4.10.14 – v6.0.37) ### Exploit Mechanics The flaws stem from weak AJAX handling in the framework, particularly a flawed "include" task that allows attackers to: 1. Bypass file-type checks via improper CSV processing, enabling unauthenticated file reads of sensitive local files. 2. Delete files without authentication by exploiting an unprotected unlink() call in the "remove" action, potentially disabling security measures like .htpasswd. 3. Execute SQL injection through unsanitized parameters in database queries, allowing attackers to dump tables or extract admin credentials. By chaining these exploits, attackers can: - Steal admin session data or credentials via SQL injection. - Authenticate as administrators, upload malicious extensions, or inject code into templates for RCE. - Disrupt site stability by deleting critical files. ### Mitigation and Patches Tassos has released patched versions of the affected extensions and framework. Site owners should: - Update immediately via Joomla’s Extension Manager. - Disable affected extensions or the nrframework plugin if patching is delayed. - Block *?option=com_ajax* endpoints at the web server or WAF level. - Monitor logs for suspicious AJAX calls and scan for signs of compromise (e.g., unexpected file changes). ### Broader Implications This disclosure underscores the ongoing risks in third-party Joomla extensions, particularly those with lax input validation and direct filesystem access. Framework developers are urged to harden AJAX endpoints and enforce stricter security practices, while Joomla users should audit extensions regularly and prioritize automated updates. No CVEs have been assigned yet, but the vulnerabilities demand urgent attention due to their potential for full site compromise.
INCIDENT DETAILS -
TYPE
SQL InjectionUnauthenticated File ReadUnauthenticated File DeletionRemote Code Execution (RCE)Privilege Escalation
IMPACT
Data Compromised: Admin session data, credentials, sensitive local filesSystems Affected: Joomla websites using vulnerable extensions or the Novarain/Tassos FrameworkOperational Impact: Potential site disruption due to deleted critical files, RCE, or admin account takeoverBrand Reputation Impact: Potential damage due to site compromise or data theftIdentity Theft Risk: Possible if admin credentials or PII are exposed
DATA BREACH
Admin credentialsSession dataSensitive local filesSensitivity Of Data: High (admin credentials, session data, potentially PII)Personally Identifiable Information: Possible if admin credentials or session data contain PII
JANUARY 2026
750Before Incident
DECEMBER 2025
750Before Incident
NOVEMBER 2025
750Before Incident
OCTOBER 2025
750Before Incident
SEPTEMBER 2025
750Before Incident
AUGUST 2025
750Before Incident
JULY 2025
750Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for SDC ?
?
What was SDC's A.I Rankiteo Cyber Score in May 2026 ?
?
What was SDC's A.I Rankiteo Cyber Score in April 2026 ?
?
What was SDC's A.I Rankiteo Cyber Score in March 2026 ?
?
What was SDC's A.I Rankiteo Cyber Score in February 2026 ?
?
What was SDC's A.I Rankiteo Cyber Score in January 2026 ?
?
What was SDC's A.I Rankiteo Cyber Score in December 2025 ?
?
What was SDC's A.I Rankiteo Cyber Score in November 2025 ?
?
What was SDC's A.I Rankiteo Cyber Score in October 2025 ?
?
What was SDC's A.I Rankiteo Cyber Score in September 2025 ?
?
What was SDC's A.I Rankiteo Cyber Score in August 2025 ?
?
What was SDC's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on SDC's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with SDC ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view SDC's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?