« Back to list

Balbooa

Balbooa Gridbox: vulnerabilities and CVEs

Balbooa Gridbox has 13 published vulnerabilities, 12 of them in the last 12 months. 8 are rated critical and 0 are listed by CISA as actively exploited.

CVEs13
Last 12 months12
Critical8
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-65947High (7.3)0.19%—Jul 29, 2026
Joomla Extension - balbooa.com - Various CSRF vectors in the admin interface in Gridbox < 2.20.2
CVE-2026-65888Critical (10)0.52%—Jul 29, 2026
Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2 - The socialLogin method allows actors to login as any given user on the target site.
CVE-2026-65887Critical (10)0.52%—Jul 29, 2026
Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2 - The resetPassword method allows actors to reset any user password, allowing to login and act as these users - excluding…
CVE-2026-65886Critical (9.2)0.55%—Jul 29, 2026
Joomla Extension - balbooa.com - Unauthenticated arbitrary file read in Gridbox < 2.20.2 - The photo viewer allows unauthenticated attackers to view arbitrary files.
CVE-2026-66490Medium (6.1)0.27%—Jul 29, 2026
Joomla Extension - balbooa.com - Stored cross-site scripting via a comment avatar in Gridbox < 2.20.2
CVE-2026-66489Medium (5.3)0.35%—Jul 29, 2026
Joomla Extension - balbooa.com - Various unauthenticated file system disclosure in Gridbox < 2.20.2
CVE-2026-66488Medium (5.3)0.34%—Jul 29, 2026
Joomla Extension - balbooa.com - Payment bypass in Gridbox < 2.20.2
CVE-2026-65890Critical (9.2)0.50%—Jul 29, 2026
Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 - Multiple SQLi vectors allow unauthenticated actors to inject SQL in queries.
CVE-2026-65889Critical (9.2)0.44%—Jul 29, 2026
Joomla Extension - balbooa.com - Unauthenticated recursive directory deletion < 2.20.2 - The generateNewApp method allows actors to recursively delete directories.
CVE-2026-65885Critical (9.4)0.52%—Jul 29, 2026
Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 - File upload methods allows authenticated attackers to upload arbitrary files. Turns into an authenticated RCE if combined with…
CVE-2026-65884Critical (10)0.52%—Jul 29, 2026
Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The registration method allows users provided usergroup IDs, allowing unauthenticated actors to register new accounts with administrative…
CVE-2026-61425Critical (9.4)0.57%—Jul 20, 2026
Joomla Extension - balbooa.com - Authentication bypass in Gridbox < 1.6.0 - The Joomla extension Gridbox is vulnerable an authenticated bypass, potentially leading to full admin access.
CVE-2018-11690Medium (6.1)34%—Jun 14, 2018
The Balbooa Gridbox extension version 2.4.0 and previous versions for Joomla! is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1190 Exploit Public-Facing Application6
  2. T1005 Data from Local System2
  3. T1210 Exploitation of Remote Services2
  4. T1078 Valid Accounts1
  5. T1078.001 Default Accounts1
  6. T1098.001 Additional Cloud Credentials1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Balbooa