Search Results (14 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-65887 2 Balbooa, Balbooa.com 2 Gridbox, Gridbox Extension For Joomla 2026-07-31 9.8 Critical
Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2 - The resetPassword method allows actors to reset any user password, allowing to login and act as these users - excluding super admins.
CVE-2026-65888 2 Balbooa, Balbooa.com 2 Gridbox, Gridbox Extension For Joomla 2026-07-31 9.8 Critical
Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2 - The socialLogin method allows actors to login as any given user on the target site.
CVE-2026-66489 2 Balbooa, Balbooa.com 2 Gridbox, Gridbox Extension For Joomla 2026-07-30 5.3 Medium
Joomla Extension - balbooa.com - Various unauthenticated file system disclosure in Gridbox < 2.20.2
CVE-2026-65947 2 Balbooa, Balbooa.com 2 Gridbox, Gridbox Extension For Joomla 2026-07-30 7.3 High
Joomla Extension - balbooa.com - Various CSRF vectors in the admin interface in Gridbox < 2.20.2
CVE-2026-66488 2 Balbooa, Balbooa.com 2 Gridbox, Gridbox Extension For Joomla 2026-07-30 5.3 Medium
Joomla Extension - balbooa.com - Payment bypass in Gridbox < 2.20.2
CVE-2026-65886 2 Balbooa, Balbooa.com 2 Gridbox, Gridbox Extension For Joomla 2026-07-29 7.5 High
Joomla Extension - balbooa.com - Unauthenticated arbitrary file read in Gridbox < 2.20.2 - The photo viewer allows unauthenticated attackers to view arbitrary files.
CVE-2026-66490 2 Balbooa, Balbooa.com 2 Gridbox, Gridbox Extension For Joomla 2026-07-29 6.1 Medium
Joomla Extension - balbooa.com - Stored cross-site scripting via a comment avatar in Gridbox < 2.20.2
CVE-2026-65889 2 Balbooa, Balbooa.com 2 Gridbox, Gridbox Extension For Joomla 2026-07-29 7.5 High
Joomla Extension - balbooa.com - Unauthenticated recursive directory deletion < 2.20.2 - The generateNewApp method allows actors to recursively delete directories.
CVE-2026-65890 2 Balbooa, Balbooa.com 2 Gridbox, Gridbox Extension For Joomla 2026-07-29 9.8 Critical
Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 - Multiple SQLi vectors allow unauthenticated actors to inject SQL in queries.
CVE-2026-65885 2 Balbooa, Balbooa.com 2 Gridbox, Gridbox Extension For Joomla 2026-07-29 8.8 High
Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 - File upload methods allows authenticated attackers to upload arbitrary files. Turns into an authenticated RCE if combined with CVE-2026-65884 as the required account can be created by the attacker.
CVE-2026-65884 2 Balbooa, Balbooa.com 2 Gridbox, Gridbox Extension For Joomla 2026-07-29 9.8 Critical
Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The registration method allows users provided usergroup IDs, allowing unauthenticated actors to register new accounts with administrative permissions.
CVE-2026-56291 2 Balbooa, Balbooa.com 2 Forms, Balbooa.com Balbooa Forms Extension For Joomla 2026-07-23 9.8 Critical
Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
CVE-2021-47930 1 Balbooa 1 Balbooa Joomla Forms Builder 2026-05-12 8.2 High
Balbooa Joomla Forms Builder 2.0.6 contains an unauthenticated SQL injection vulnerability in the form submission handler that allows remote attackers to execute arbitrary SQL queries. Attackers can send POST requests to the com_baforms component with malicious JSON payloads in the 'id' field parameter to extract sensitive database information.
CVE-2018-11690 1 Balbooa 1 Gridbox 2024-11-21 N/A
The Balbooa Gridbox extension version 2.4.0 and previous versions for Joomla! is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability via a crafted URL to execute script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.