« Back to list

Balbooa

Balbooa Forms: vulnerabilities and CVEs

Balbooa Forms has 10 published vulnerabilities, 9 of them in the last 12 months. 4 are rated critical and 1 are listed by CISA as actively exploited.

CVEs10
Last 12 months9
Critical4
Actively exploited1

All vulnerabilities in the catalogue →⭐ Follow this technology

🔴 Actively exploited (CISA KEV)

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-56291Critical (10)15%⚠ Active exploitationJul 9, 2026
Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading…

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-102425Critical (9.5)0.32%—Sep 29, 2026
Joomla Extension - balbooa.com - Unauthenticated RCE via field shortcode injection in Balbooa Forms < 2.4.3.4 - Balbooa Forms supports administrator-defined PHP code which runs after a public form submission. The…
CVE-2026-102424High (8.9)0.37%—Sep 29, 2026
Joomla Extension - balbooa.com - Unauthenticated path traversal exfiltrates local files through auto-reply attachments in Balbooa Forms < 2.4.3.4 - Balbooa Forms accepts upload-field state as Guest-controlled JSON…
CVE-2026-101127High (8.6)0.32%—Sep 29, 2026
Joomla Extension - balbooa.com - Unauthenticated upload filename stored XSS in Balbooa Forms < 2.4.3.4 - The public form upload endpoint validates the uploaded file's extension and detected MIME type, but stores the…
CVE-2026-101126Medium (6.9)0.37%—Sep 29, 2026
Joomla Extension - balbooa.com - File meta data tampering in Balbooa Forms < 2.4.3.4 - The final form submission processes JSON arrays per upload field, checking only that IDs are numeric. Client-supplied filenames and…
CVE-2026-101112Medium (6.9)0.29%—Sep 29, 2026
Joomla Extension - balbooa.com - Unauthorized Deletion of Attachments in Balbooa Forms < 2.4.3.4 - The public removeTmpAttachment action accepts an integer attachment ID and deletes the matching database row and file.…
CVE-2026-67363High (7.7)0.56%—Aug 19, 2026
Joomla Extension - balbooa.com - Pre-auth Payment Amount Tampering in Balbooa Forms < 2.4.3.2 - The stripeCharges and payAuthorize endpoints accept the charge total from a client-controlled request parameter and forward…
CVE-2026-67364Critical (10)0.50%—Aug 19, 2026
Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 - The form's optional custom-PHP post-submission handler is executed via eval(). The [URL parameter = X] shortcode is substituted…
CVE-2026-65880Critical (10)0.77%—Jul 28, 2026
Joomla Extension - balbooa.com - Unauthenticated remote code execution in Balbooa Forms < 2.4.3 - An insecure form processing logic allowed code execution for forms that include the signature field type.
CVE-2026-56291Critical (10)15%⚠ Active exploitationJul 9, 2026
Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading…
CVE-2025-49485High (8.6)0.26%—Jul 18, 2025
A SQL injection vulnerability in the Balbooa Forms plugin 1.0.0-2.3.1.1 for Joomla allows privileged users to execute arbitrary SQL commands via the 'id' parameter.

🎯 How it gets exploited (ATT&CK techniques)

  1. T1190 Exploit Public-Facing Application8
  2. T1005 Data from Local System3
  3. T1059 Command and Scripting Interpreter3
  4. T1059.007 JavaScript1
  5. T1189 Drive-by Compromise1
  6. T1210 Exploitation of Remote Services1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Balbooa