VYPR

Forms

by Balbooa

CVEs (3)

  • CVE-2026-67363HigAug 19, 2026
    risk 0.50cvss —epss 0.01

    Joomla Extension - balbooa.com - Pre-auth Payment Amount Tampering in Balbooa Forms < 2.4.3.2 - The stripeCharges and payAuthorize endpoints accept the charge total from a client-controlled request parameter and forward it to the payment gateway without recomputing it from the…

  • CVE-2026-56291CriKEVJul 9, 2026
    risk 0.18cvss 9.8epss 0.15

    Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

  • CVE-2026-65880CriJul 28, 2026
    risk 0.00cvss —epss 0.01

    Joomla Extension - balbooa.com - Unauthenticated remote code execution in Balbooa Forms < 2.4.3 - An insecure form processing logic allowed code execution for forms that include the signature field type.