Known Vulnerabilities for products from Balbooa
Listed below are 13 of the newest known vulnerabilities associated with the vendor "Balbooa".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-67364 json | Not Provided | 2026-08-19 | 2026-08-21 | |
| CVE-2026-67363 json | Not Provided | 2026-08-19 | 2026-08-20 | |
| CVE-2026-66490 json | Not Provided | 2026-07-29 | 2026-07-29 | |
| CVE-2026-66489 json | Not Provided | 2026-07-29 | 2026-07-31 | |
| CVE-2026-66488 json | Joomla Extension - balbooa.com - Payment bypass in Gridbox < 2.20.2 | Not Provided | 2026-07-29 | 2026-08-05 |
| CVE-2026-65947 json | Not Provided | 2026-07-29 | 2026-07-31 | |
| CVE-2026-65890 json | Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 - Multiple SQLi vectors allow unauthentica... | Not Provided | 2026-07-29 | 2026-08-05 |
| CVE-2026-65889 json | Joomla Extension - balbooa.com - Unauthenticated recursive directory deletion < 2.20.2 - The generateNewApp method allows act... | Not Provided | 2026-07-29 | 2026-08-05 |
| CVE-2026-65888 json | Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2 - The socialLogin method allows actors to... | Not Provided | 2026-07-29 | 2026-08-05 |
| CVE-2026-65887 json | Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2 - The resetPassword method allo... | Not Provided | 2026-07-29 | 2026-08-05 |
| CVE-2026-65886 json | Joomla Extension - balbooa.com - Unauthenticated arbitrary file read in Gridbox < 2.20.2 - The photo viewer allows unauthenti... | Not Provided | 2026-07-29 | 2026-08-05 |
| CVE-2026-65885 json | Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 - File upload methods allows authent... | Not Provided | 2026-07-29 | 2026-08-05 |
| CVE-2026-65884 json | Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The registration method allows users provided use... | Not Provided | 2026-07-29 | 2026-08-05 |
| CVE-2026-56291 json | Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balboo... | Not Provided | 2026-07-09 | 2026-07-24 |
| CVE-2018-11690 json | The Balbooa Gridbox extension version 2.4.0 and previous versions for Joomla! is vulnerable to cross-site scripting, caused b... | 6.1 - MEDIUM | 2018-06-14 | 2019-03-14 |