What is CVE-2026-66490?
CVE-2026-66490 is a Stored cross-site scripting vulnerability in the Gridbox Joomla extension by Balbooa.com, affecting versions prior to 2.20.2. The flaw is exploitable via a comment avatar, potentially allowing remote code execution or session hijacking. Users of Gridbox should immediately update to the latest version to mitigate the risk.
Azərbaycanca: CVE-2026-66490, Joomla üçün Balbooa.com tərəfindən hazırlanmış Gridbox komponentinin 2.20.2-dən əvvəlki versiyalarını təsir edən saxlanılmış XSS (Stored cross-site scripting) zəifliyidir. Bu zəiflik şərh avatarı vasitəsilə istismar edilir və uzaqdan kod icrasına və ya sessiya oğurlanmasına səbəb ola bilər. Gridbox istifadəçiləri təcili olaraq ən son versiyaya yeniləməlidirlər.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which Gridbox versions are affected by CVE-2026-66490?
This vulnerability affects versions of the Gridbox component by Balbooa.com prior to 2.20.2.
How is CVE-2026-66490 exploited?
This stored XSS vulnerability is exploited via a comment avatar.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.