Known Vulnerabilities for products from Balbooa
Listed below are 18 of the newest known vulnerabilities associated with the vendor "Balbooa".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-102784 json | Not Provided | 2026-10-08 | 2026-10-08 | |
| CVE-2026-102783 json | Not Provided | 2026-10-08 | 2026-10-08 | |
| CVE-2026-102425 json | Joomla Extension - balbooa.com - Unauthenticated RCE via field shortcode injection in Balbooa Forms < 2.4.3.4 - Balbooa Forms... | Not Provided | 2026-09-29 | 2026-10-06 |
| CVE-2026-102424 json | Not Provided | 2026-09-29 | 2026-10-01 | |
| CVE-2026-101127 json | Joomla Extension - balbooa.com - Unauthenticated upload filename stored XSS in Balbooa Forms < 2.4.3.4 - The public form uplo... | Not Provided | 2026-09-29 | 2026-10-06 |
| CVE-2026-101126 json | Joomla Extension - balbooa.com - File meta data tampering in Balbooa Forms < 2.4.3.4 - The final form submission processes JS... | Not Provided | 2026-09-29 | 2026-10-06 |
| CVE-2026-101112 json | Not Provided | 2026-09-29 | 2026-09-30 | |
| CVE-2026-67364 json | Not Provided | 2026-08-19 | 2026-09-29 | |
| CVE-2026-67363 json | Not Provided | 2026-08-19 | 2026-08-21 | |
| CVE-2026-66490 json | Joomla Extension - balbooa.com - Stored cross-site scripting via a comment avatar in Gridbox < 2.20.2 | Not Provided | 2026-07-29 | 2026-08-05 |
| CVE-2026-66489 json | Joomla Extension - balbooa.com - Various unauthenticated file system disclosure in Gridbox < 2.20.2 | Not Provided | 2026-07-29 | 2026-08-05 |
| CVE-2026-66488 json | Joomla Extension - balbooa.com - Payment bypass in Gridbox < 2.20.2 | Not Provided | 2026-07-29 | 2026-08-05 |
| CVE-2026-65947 json | Joomla Extension - balbooa.com - Various CSRF vectors in the admin interface in Gridbox < 2.20.2 | Not Provided | 2026-07-29 | 2026-08-05 |
| CVE-2026-65890 json | Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 - Multiple SQLi vectors allow unauthentica... | Not Provided | 2026-07-29 | 2026-08-05 |
| CVE-2026-65889 json | Joomla Extension - balbooa.com - Unauthenticated recursive directory deletion < 2.20.2 - The generateNewApp method allows act... | Not Provided | 2026-07-29 | 2026-08-05 |
| CVE-2026-65888 json | Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2 - The socialLogin method allows actors to... | Not Provided | 2026-07-29 | 2026-08-05 |
| CVE-2026-65887 json | Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2 - The resetPassword method allo... | Not Provided | 2026-07-29 | 2026-08-05 |
| CVE-2026-65886 json | Joomla Extension - balbooa.com - Unauthenticated arbitrary file read in Gridbox < 2.20.2 - The photo viewer allows unauthenti... | Not Provided | 2026-07-29 | 2026-08-05 |
| CVE-2026-65885 json | Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 - File upload methods allows authent... | Not Provided | 2026-07-29 | 2026-08-05 |
| CVE-2026-65884 json | Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The registration method allows users provided use... | Not Provided | 2026-07-29 | 2026-08-05 |