What is CVE-2026-65890?
An unauthenticated SQL injection vulnerability has been discovered in the Gridbox extension for Joomla, affecting versions before 2.20.2. This flaw allows unauthenticated actors to inject SQL code into queries through multiple vectors, potentially gaining unauthorized database access. Users are strongly advised to update the Gridbox extension to version 2.20.2 or later immediately.
Azərbaycanca: Joomla üçün Gridbox genişləndirilməsinin 2.20.2-dən əvvəlki versiyalarında autentifikasiya olunmamış SQL injection zəifliyi aşkarlanıb. Bu boşluqdan istifadə edən hücumçular sorğulara SQL kodu əlavə edərək verilənlər bazasına icazəsiz giriş əldə edə bilərlər. İstifadəçilərə Gridbox genişləndirilməsini dərhal 2.20.2 və ya daha yeni versiyaya yeniləmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Which Joomla component is affected by CVE-2026-65890?
This vulnerability affects the Gridbox extension for Joomla.
To which version should Gridbox be updated to protect against CVE-2026-65890?
Users should update the Gridbox extension to version 2.20.2 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.