Balbooa
Products
3- 12 CVEs
- 2 CVEs
- 1 CVE
Recent CVEs
15| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-65888 | Cri | 0.64 | 9.8 | 0.00 | Jul 29, 2026 | Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2 - The socialLogin method allows actors to login as any given user on the target site. | ||
| CVE-2026-65887 | Cri | 0.64 | 9.8 | 0.00 | Jul 29, 2026 | Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2 - The resetPassword method allows actors to reset any user password, allowing to login and act as these users - excluding super admins. | ||
| CVE-2026-65890 | Cri | 0.64 | 9.8 | 0.00 | Jul 29, 2026 | Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 - Multiple SQLi vectors allow unauthenticated actors to inject SQL in queries. | ||
| CVE-2026-65884 | Cri | 0.64 | 9.8 | 0.00 | Jul 29, 2026 | Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The registration method allows users provided usergroup IDs, allowing unauthenticated actors to register new accounts with administrative permissions. | ||
| CVE-2026-65885 | Hig | 0.57 | 8.8 | 0.00 | Jul 29, 2026 | Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 - File upload methods allows authenticated attackers to upload arbitrary files. Turns into an authenticated RCE if combined with CVE-2026-65884 as the required account can be created by the… | ||
| CVE-2021-47930 | Hig | 0.53 | 8.2 | 0.00 | May 10, 2026 | Balbooa Joomla Forms Builder 2.0.6 contains an unauthenticated SQL injection vulnerability in the form submission handler that allows remote attackers to execute arbitrary SQL queries. Attackers can send POST requests to the com_baforms component with malicious JSON payloads in… | ||
| CVE-2026-65886 | Hig | 0.49 | 7.5 | 0.00 | Jul 29, 2026 | Joomla Extension - balbooa.com - Unauthenticated arbitrary file read in Gridbox < 2.20.2 - The photo viewer allows unauthenticated attackers to view arbitrary files. | ||
| CVE-2026-65889 | Hig | 0.49 | 7.5 | 0.00 | Jul 29, 2026 | Joomla Extension - balbooa.com - Unauthenticated recursive directory deletion < 2.20.2 - The generateNewApp method allows actors to recursively delete directories. | ||
| CVE-2026-65947 | Hig | 0.47 | 7.3 | 0.00 | Jul 29, 2026 | Joomla Extension - balbooa.com - Various CSRF vectors in the admin interface in Gridbox < 2.20.2 | ||
| CVE-2018-11690 | Med | 0.42 | 6.1 | 0.34 | Jun 14, 2018 | The Balbooa Gridbox extension version 2.4.0 and previous versions for Joomla! is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability via a crafted URL to execute script in a victim's Web… | ||
| CVE-2026-66490 | Med | 0.40 | 6.1 | 0.00 | Jul 29, 2026 | Joomla Extension - balbooa.com - Stored cross-site scripting via a comment avatar in Gridbox < 2.20.2 | ||
| CVE-2026-66489 | Med | 0.34 | 5.3 | 0.00 | Jul 29, 2026 | Joomla Extension - balbooa.com - Various unauthenticated file system disclosure in Gridbox < 2.20.2 | ||
| CVE-2026-66488 | Med | 0.34 | 5.3 | 0.00 | Jul 29, 2026 | Joomla Extension - balbooa.com - Payment bypass in Gridbox < 2.20.2 | ||
| CVE-2026-56291 | Cri | 0.18 | 9.8 | 0.76 | KEV | Jul 9, 2026 | Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE. | |
| CVE-2026-65880 | Cri | 0.00 | — | 0.00 | Jul 28, 2026 | Joomla Extension - balbooa.com - Unauthenticated remote code execution in Balbooa Forms < 2.4.3 - An insecure form processing logic allowed code execution for forms that include the signature field type. |
- risk 0.64cvss 9.8epss 0.00
Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2 - The socialLogin method allows actors to login as any given user on the target site.
- risk 0.64cvss 9.8epss 0.00
Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2 - The resetPassword method allows actors to reset any user password, allowing to login and act as these users - excluding super admins.
- risk 0.64cvss 9.8epss 0.00
Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 - Multiple SQLi vectors allow unauthenticated actors to inject SQL in queries.
- risk 0.64cvss 9.8epss 0.00
Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The registration method allows users provided usergroup IDs, allowing unauthenticated actors to register new accounts with administrative permissions.
- risk 0.57cvss 8.8epss 0.00
Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 - File upload methods allows authenticated attackers to upload arbitrary files. Turns into an authenticated RCE if combined with CVE-2026-65884 as the required account can be created by the…
- risk 0.53cvss 8.2epss 0.00
Balbooa Joomla Forms Builder 2.0.6 contains an unauthenticated SQL injection vulnerability in the form submission handler that allows remote attackers to execute arbitrary SQL queries. Attackers can send POST requests to the com_baforms component with malicious JSON payloads in…
- risk 0.49cvss 7.5epss 0.00
Joomla Extension - balbooa.com - Unauthenticated arbitrary file read in Gridbox < 2.20.2 - The photo viewer allows unauthenticated attackers to view arbitrary files.
- risk 0.49cvss 7.5epss 0.00
Joomla Extension - balbooa.com - Unauthenticated recursive directory deletion < 2.20.2 - The generateNewApp method allows actors to recursively delete directories.
- risk 0.47cvss 7.3epss 0.00
Joomla Extension - balbooa.com - Various CSRF vectors in the admin interface in Gridbox < 2.20.2
- risk 0.42cvss 6.1epss 0.34
The Balbooa Gridbox extension version 2.4.0 and previous versions for Joomla! is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability via a crafted URL to execute script in a victim's Web…
- risk 0.40cvss 6.1epss 0.00
Joomla Extension - balbooa.com - Stored cross-site scripting via a comment avatar in Gridbox < 2.20.2
- risk 0.34cvss 5.3epss 0.00
Joomla Extension - balbooa.com - Various unauthenticated file system disclosure in Gridbox < 2.20.2
- risk 0.34cvss 5.3epss 0.00
Joomla Extension - balbooa.com - Payment bypass in Gridbox < 2.20.2
- risk 0.18cvss 9.8epss 0.76
Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
- risk 0.00cvss —epss 0.00
Joomla Extension - balbooa.com - Unauthenticated remote code execution in Balbooa Forms < 2.4.3 - An insecure form processing logic allowed code execution for forms that include the signature field type.