VYPR
Vendor

Balbooa

Products
3
CVEs
15
Across products
15
Status
Private

Products

3

Recent CVEs

15
  • CVE-2026-65888CriJul 29, 2026
    risk 0.64cvss 9.8epss 0.00

    Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2 - The socialLogin method allows actors to login as any given user on the target site.

  • CVE-2026-65887CriJul 29, 2026
    risk 0.64cvss 9.8epss 0.00

    Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2 - The resetPassword method allows actors to reset any user password, allowing to login and act as these users - excluding super admins.

  • CVE-2026-65890CriJul 29, 2026
    risk 0.64cvss 9.8epss 0.00

    Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 - Multiple SQLi vectors allow unauthenticated actors to inject SQL in queries.

  • CVE-2026-65884CriJul 29, 2026
    risk 0.64cvss 9.8epss 0.00

    Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The registration method allows users provided usergroup IDs, allowing unauthenticated actors to register new accounts with administrative permissions.

  • CVE-2026-65885HigJul 29, 2026
    risk 0.57cvss 8.8epss 0.00

    Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 - File upload methods allows authenticated attackers to upload arbitrary files. Turns into an authenticated RCE if combined with CVE-2026-65884 as the required account can be created by the…

  • CVE-2021-47930HigMay 10, 2026
    risk 0.53cvss 8.2epss 0.00

    Balbooa Joomla Forms Builder 2.0.6 contains an unauthenticated SQL injection vulnerability in the form submission handler that allows remote attackers to execute arbitrary SQL queries. Attackers can send POST requests to the com_baforms component with malicious JSON payloads in…

  • CVE-2026-65886HigJul 29, 2026
    risk 0.49cvss 7.5epss 0.00

    Joomla Extension - balbooa.com - Unauthenticated arbitrary file read in Gridbox < 2.20.2 - The photo viewer allows unauthenticated attackers to view arbitrary files.

  • CVE-2026-65889HigJul 29, 2026
    risk 0.49cvss 7.5epss 0.00

    Joomla Extension - balbooa.com - Unauthenticated recursive directory deletion < 2.20.2 - The generateNewApp method allows actors to recursively delete directories.

  • CVE-2026-65947HigJul 29, 2026
    risk 0.47cvss 7.3epss 0.00

    Joomla Extension - balbooa.com - Various CSRF vectors in the admin interface in Gridbox < 2.20.2

  • CVE-2018-11690MedJun 14, 2018
    risk 0.42cvss 6.1epss 0.34

    The Balbooa Gridbox extension version 2.4.0 and previous versions for Joomla! is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability via a crafted URL to execute script in a victim's Web…

  • CVE-2026-66490MedJul 29, 2026
    risk 0.40cvss 6.1epss 0.00

    Joomla Extension - balbooa.com - Stored cross-site scripting via a comment avatar in Gridbox < 2.20.2

  • CVE-2026-66489MedJul 29, 2026
    risk 0.34cvss 5.3epss 0.00

    Joomla Extension - balbooa.com - Various unauthenticated file system disclosure in Gridbox < 2.20.2

  • CVE-2026-66488MedJul 29, 2026
    risk 0.34cvss 5.3epss 0.00

    Joomla Extension - balbooa.com - Payment bypass in Gridbox < 2.20.2

  • CVE-2026-56291CriKEVJul 9, 2026
    risk 0.18cvss 9.8epss 0.76

    Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

  • CVE-2026-65880CriJul 28, 2026
    risk 0.00cvss epss 0.00

    Joomla Extension - balbooa.com - Unauthenticated remote code execution in Balbooa Forms < 2.4.3 - An insecure form processing logic allowed code execution for forms that include the signature field type.