« Volver al listado

Balbooa

Balbooa Gridbox: vulnerabilidades y CVE

Balbooa Gridbox tiene 13 vulnerabilidades publicadas, 12 de ellas en los últimos 12 meses. 8 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE13
Últimos 12 meses12
Críticas8
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-65947Alta (7.3)0.19%—29 jul 2026
Joomla Extension - balbooa.com - Various CSRF vectors in the admin interface in Gridbox < 2.20.2
CVE-2026-65888Crítica (10)0.52%—29 jul 2026
Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2 - The socialLogin method allows actors to login as any given user on the target site.
CVE-2026-65887Crítica (10)0.52%—29 jul 2026
Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2 - The resetPassword method allows actors to reset any user password, allowing to login and act as these users - excluding…
CVE-2026-65886Crítica (9.2)0.55%—29 jul 2026
Joomla Extension - balbooa.com - Unauthenticated arbitrary file read in Gridbox < 2.20.2 - The photo viewer allows unauthenticated attackers to view arbitrary files.
CVE-2026-66490Media (6.1)0.27%—29 jul 2026
Joomla Extension - balbooa.com - Stored cross-site scripting via a comment avatar in Gridbox < 2.20.2
CVE-2026-66489Media (5.3)0.35%—29 jul 2026
Joomla Extension - balbooa.com - Various unauthenticated file system disclosure in Gridbox < 2.20.2
CVE-2026-66488Media (5.3)0.34%—29 jul 2026
Joomla Extension - balbooa.com - Payment bypass in Gridbox < 2.20.2
CVE-2026-65890Crítica (9.2)0.50%—29 jul 2026
Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 - Multiple SQLi vectors allow unauthenticated actors to inject SQL in queries.
CVE-2026-65889Crítica (9.2)0.44%—29 jul 2026
Joomla Extension - balbooa.com - Unauthenticated recursive directory deletion < 2.20.2 - The generateNewApp method allows actors to recursively delete directories.
CVE-2026-65885Crítica (9.4)0.52%—29 jul 2026
Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 - File upload methods allows authenticated attackers to upload arbitrary files. Turns into an authenticated RCE if combined with…
CVE-2026-65884Crítica (10)0.52%—29 jul 2026
Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The registration method allows users provided usergroup IDs, allowing unauthenticated actors to register new accounts with administrative…
CVE-2026-61425Crítica (9.4)0.57%—20 jul 2026
Joomla Extension - balbooa.com - Authentication bypass in Gridbox < 1.6.0 - The Joomla extension Gridbox is vulnerable an authenticated bypass, potentially leading to full admin access.
CVE-2018-11690Media (6.1)34%—14 jun 2018
The Balbooa Gridbox extension version 2.4.0 and previous versions for Joomla! is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application6
  2. T1005 Data from Local System2
  3. T1210 Exploitation of Remote Services2
  4. T1078 Valid Accounts1
  5. T1078.001 Default Accounts1
  6. T1098.001 Additional Cloud Credentials1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Balbooa