Balbooa
Balbooa Forms: vulnerabilities and CVEs
Balbooa Forms has 10 published vulnerabilities, 9 of them in the last 12 months. 4 are rated critical and 1 are listed by CISA as actively exploited.
CVEs10
Last 12 months9
Critical4
Actively exploited1
All vulnerabilities in the catalogue →⭐ Follow this technology
🔴 Actively exploited (CISA KEV)
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-56291 | Critical (10) | 15% | ⚠ Active exploitation | Jul 9, 2026 | Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading… |
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-102425 | Critical (9.5) | 0.32% | — | Sep 29, 2026 | Joomla Extension - balbooa.com - Unauthenticated RCE via field shortcode injection in Balbooa Forms < 2.4.3.4 - Balbooa Forms supports administrator-defined PHP code which runs after a public form submission. The… |
| CVE-2026-102424 | High (8.9) | 0.37% | — | Sep 29, 2026 | Joomla Extension - balbooa.com - Unauthenticated path traversal exfiltrates local files through auto-reply attachments in Balbooa Forms < 2.4.3.4 - Balbooa Forms accepts upload-field state as Guest-controlled JSON… |
| CVE-2026-101127 | High (8.6) | 0.32% | — | Sep 29, 2026 | Joomla Extension - balbooa.com - Unauthenticated upload filename stored XSS in Balbooa Forms < 2.4.3.4 - The public form upload endpoint validates the uploaded file's extension and detected MIME type, but stores the… |
| CVE-2026-101126 | Medium (6.9) | 0.37% | — | Sep 29, 2026 | Joomla Extension - balbooa.com - File meta data tampering in Balbooa Forms < 2.4.3.4 - The final form submission processes JSON arrays per upload field, checking only that IDs are numeric. Client-supplied filenames and… |
| CVE-2026-101112 | Medium (6.9) | 0.29% | — | Sep 29, 2026 | Joomla Extension - balbooa.com - Unauthorized Deletion of Attachments in Balbooa Forms < 2.4.3.4 - The public removeTmpAttachment action accepts an integer attachment ID and deletes the matching database row and file.… |
| CVE-2026-67363 | High (7.7) | 0.56% | — | Aug 19, 2026 | Joomla Extension - balbooa.com - Pre-auth Payment Amount Tampering in Balbooa Forms < 2.4.3.2 - The stripeCharges and payAuthorize endpoints accept the charge total from a client-controlled request parameter and forward… |
| CVE-2026-67364 | Critical (10) | 0.50% | — | Aug 19, 2026 | Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 - The form's optional custom-PHP post-submission handler is executed via eval(). The [URL parameter = X] shortcode is substituted… |
| CVE-2026-65880 | Critical (10) | 0.77% | — | Jul 28, 2026 | Joomla Extension - balbooa.com - Unauthenticated remote code execution in Balbooa Forms < 2.4.3 - An insecure form processing logic allowed code execution for forms that include the signature field type. |
| CVE-2026-56291 | Critical (10) | 15% | ⚠ Active exploitation | Jul 9, 2026 | Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading… |
| CVE-2025-49485 | High (8.6) | 0.26% | — | Jul 18, 2025 | A SQL injection vulnerability in the Balbooa Forms plugin 1.0.0-2.3.1.1 for Joomla allows privileged users to execute arbitrary SQL commands via the 'id' parameter. |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.