Search Results (21 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-102425 1 Balbooa.com 1 Balbooa.com Balbooa Forms Extension For Joomla 2026-09-30 N/A
Joomla Extension - balbooa.com - Unauthenticated RCE via field shortcode injection in Balbooa Forms < 2.4.3.4 - Balbooa Forms supports administrator-defined PHP code which runs after a public form submission. The feature also supports form-field shortcodes inside that PHP. Before calling `eval()`, the component replaces each shortcode with the raw value submitted by the visitor, leading to an RCE vector. A public form must use the product's optional PHP-after-submission action and interpolate an attacker-controlled field shortcode inside a double-quoted PHP string to be vulnerable.
CVE-2026-102424 1 Balbooa.com 1 Balbooa.com Balbooa Forms Extension For Joomla 2026-09-30 N/A
Joomla Extension - balbooa.com - Unauthenticated path traversal exfiltrates local files through auto-reply attachments in Balbooa Forms < 2.4.3.4 - Balbooa Forms accepts upload-field state as Guest-controlled JSON during public form submission. For every object whose `id` merely looks numeric, the component trusts the supplied `filename`, concatenates it below the configured upload directory, and adds the result to an array of local attachment paths. It does not load the referenced attachment row, verify ownership/session/form/field, require that the ID exists, canonicalize the path, or enforce containment. If the form's normal “auto reply” and “attach uploaded files” options are enabled, the component sends those local paths as email attachments to the address submitted in an email field. A Guest can therefore submit a nonexistent numeric ID plus a traversal filename such as `../../../../configuration.php` and receive any file readable by the Joomla process.
CVE-2026-101127 1 Balbooa.com 1 Balbooa.com Balbooa Forms Extension For Joomla 2026-09-30 N/A
Joomla Extension - balbooa.com - Unauthenticated upload filename stored XSS in Balbooa Forms < 2.4.3.4 - The public form upload endpoint validates the uploaded file's extension and detected MIME type, but stores the attacker-supplied original multipart filename verbatim in `#__baforms_submissions_attachments.name`. A later anonymous form submission associates that temporary attachment with the newly created submission. When an administrator opens the submission, the component's JavaScript retrieves the stored attachment record and concatenates `file.name` directly into an HTML string. The complete string is assigned to `innerHTML`.
CVE-2026-101126 1 Balbooa.com 1 Balbooa.com Balbooa Forms Extension For Joomla 2026-09-30 N/A
Joomla Extension - balbooa.com - File meta data tampering in Balbooa Forms < 2.4.3.4 - The final form submission processes JSON arrays per upload field, checking only that IDs are numeric. Client-supplied filenames and display names are trusted directly, introducing potential cross-session claiming, metadata tampering, and path traversal risks (e.g., via getFilePath())
CVE-2026-101112 1 Balbooa.com 1 Balbooa.com Balbooa Forms Extension For Joomla 2026-09-30 N/A
Joomla Extension - balbooa.com - Unauthorized Deletion of Attachments in Balbooa Forms < 2.4.3.4 - The public removeTmpAttachment action accepts an integer attachment ID and deletes the matching database row and file. The controller verifies a Joomla session token, but the model does not bind that ID to the session that uploaded the file, the current user, the form, the upload field, or the temporary state. Any guest can obtain a token for their own session, so the token prevents CSRF but does not authorize the target object.
CVE-2026-67364 1 Balbooa.com 1 Balbooa.com Balbooa Forms Extension For Joomla 2026-09-29 N/A
Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 - The form's optional custom-PHP post-submission handler is executed via eval(). The [URL parameter = X] shortcode is substituted with the raw, unescaped value of a query parameter, letting an unauthenticated attacker inject arbitrary PHP that executes server-side. The CSRF token needed to reach the endpoint is itself disclosed anonymously via a separate task, so it provides no real protection. Exploitability requires the form to have a custom-PHP handler configured (a documented builder feature) referencing that shortcode, and no reCAPTCHA on the submit button.
CVE-2026-67363 1 Balbooa.com 1 Balbooa.com Balbooa Forms Extension For Joomla 2026-08-21 N/A
Joomla Extension - balbooa.com - Pre-auth Payment Amount Tampering in Balbooa Forms < 2.4.3.2 - The stripeCharges and payAuthorize endpoints accept the charge total from a client-controlled request parameter and forward it to the payment gateway without recomputing it from the form's configured product prices. Neither endpoint enforces authentication or CSRF checks. An unauthenticated attacker can purchase any priced item for an arbitrary amount (e.g., $0.01), and can additionally forge line items, quantities, and shipping.
CVE-2026-65880 1 Balbooa.com 1 Balbooa Forms Component For Joomla 2026-08-07 N/A
Joomla Extension - balbooa.com - Unauthenticated remote code execution in Balbooa Forms < 2.4.3 - An insecure form processing logic allowed code execution for forms that include the signature field type.
CVE-2026-65887 2 Balbooa, Balbooa.com 2 Gridbox, Gridbox Extension For Joomla 2026-07-31 9.8 Critical
Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2 - The resetPassword method allows actors to reset any user password, allowing to login and act as these users - excluding super admins.
CVE-2026-65888 2 Balbooa, Balbooa.com 2 Gridbox, Gridbox Extension For Joomla 2026-07-31 9.8 Critical
Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2 - The socialLogin method allows actors to login as any given user on the target site.
CVE-2026-66489 2 Balbooa, Balbooa.com 2 Gridbox, Gridbox Extension For Joomla 2026-07-30 5.3 Medium
Joomla Extension - balbooa.com - Various unauthenticated file system disclosure in Gridbox < 2.20.2
CVE-2026-65947 2 Balbooa, Balbooa.com 2 Gridbox, Gridbox Extension For Joomla 2026-07-30 7.3 High
Joomla Extension - balbooa.com - Various CSRF vectors in the admin interface in Gridbox < 2.20.2
CVE-2026-66488 2 Balbooa, Balbooa.com 2 Gridbox, Gridbox Extension For Joomla 2026-07-30 5.3 Medium
Joomla Extension - balbooa.com - Payment bypass in Gridbox < 2.20.2
CVE-2026-65886 2 Balbooa, Balbooa.com 2 Gridbox, Gridbox Extension For Joomla 2026-07-29 7.5 High
Joomla Extension - balbooa.com - Unauthenticated arbitrary file read in Gridbox < 2.20.2 - The photo viewer allows unauthenticated attackers to view arbitrary files.
CVE-2026-66490 2 Balbooa, Balbooa.com 2 Gridbox, Gridbox Extension For Joomla 2026-07-29 6.1 Medium
Joomla Extension - balbooa.com - Stored cross-site scripting via a comment avatar in Gridbox < 2.20.2
CVE-2026-65889 2 Balbooa, Balbooa.com 2 Gridbox, Gridbox Extension For Joomla 2026-07-29 7.5 High
Joomla Extension - balbooa.com - Unauthenticated recursive directory deletion < 2.20.2 - The generateNewApp method allows actors to recursively delete directories.
CVE-2026-65890 2 Balbooa, Balbooa.com 2 Gridbox, Gridbox Extension For Joomla 2026-07-29 9.8 Critical
Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 - Multiple SQLi vectors allow unauthenticated actors to inject SQL in queries.
CVE-2026-65885 2 Balbooa, Balbooa.com 2 Gridbox, Gridbox Extension For Joomla 2026-07-29 8.8 High
Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 - File upload methods allows authenticated attackers to upload arbitrary files. Turns into an authenticated RCE if combined with CVE-2026-65884 as the required account can be created by the attacker.
CVE-2026-65884 2 Balbooa, Balbooa.com 2 Gridbox, Gridbox Extension For Joomla 2026-07-29 9.8 Critical
Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The registration method allows users provided usergroup IDs, allowing unauthenticated actors to register new accounts with administrative permissions.
CVE-2026-61425 1 Balbooa.com 1 Gridbox Extension For Joomla 2026-07-23 N/A
Joomla Extension - balbooa.com - Authentication bypass in Gridbox < 1.6.0 - The Joomla extension Gridbox is vulnerable an authenticated bypass, potentially leading to full admin access.