EN
en direct
éditeur

Balbooa

9
vulnérabilités suivies
1
en exploitation active
5
critiques
29 juillet 2026
dernière publication
cve

Veille des vulnérabilités

identifiantvulnérabilitésévéritépublié
CVE-2026-65884Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The registration method allows users provided usergroup IDs, allowing unauthenticated actors to register new accounts with administrative permissions.Balbooa Gridbox Critique CVSS 9.8 29/07 CVE-2026-65885Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 - File upload methods allows authenticated attackers to upload arbitrary files. Turns into an authenticated RCE if combined with CVE-2026-65884 as the required account can be created by the attacker.Balbooa Gridbox Élevée CVSS 8.8 29/07 CVE-2026-65886Joomla Extension - balbooa.com - Unauthenticated arbitrary file read in Gridbox < 2.20.2 - The photo viewer allows unauthenticated attackers to view arbitrary files.Balbooa Gridbox Élevée CVSS 7.5 29/07 CVE-2026-65887Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2 - The resetPassword method allows actors to reset any user password, allowing to login and act as these users - excluding super admins.Balbooa Gridbox Critique CVSS 9.8 29/07 CVE-2026-65888Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2 - The socialLogin method allows actors to login as any given user on the target site.Balbooa Gridbox Critique CVSS 9.8 29/07 CVE-2026-65889Joomla Extension - balbooa.com - Unauthenticated recursive directory deletion < 2.20.2 - The generateNewApp method allows actors to recursively delete directories.Balbooa Gridbox Élevée CVSS 7.5 29/07 CVE-2026-65890Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 - Multiple SQLi vectors allow unauthenticated actors to inject SQL in queries.Balbooa Gridbox Critique CVSS 9.8 29/07 CVE-2026-65947Joomla Extension - balbooa.com - Various CSRF vectors in the admin interface in Gridbox < 2.20.2Balbooa Gridbox Élevée CVSS 7.3 29/07 CVE-2026-56291Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.Balbooa Forms Critique CVSS 9.8 10/07

Tapez au moins deux caractères.

naviguer ouvrir esc fermer