What is CVE-2026-67364?
CVE-2026-67364 is a critical pre-auth PHP code injection vulnerability in the Balbooa Forms extension for Joomla. The flaw exists in the optional custom-PHP post-submission handler, where eval() is used with improperly sanitized input, allowing unauthenticated remote code execution. Immediate update to version 2.4.3.2 or later is required.
Azərbaycanca: CVE-2026-67364 Joomla üçün Balbooa Forms genişləndirilməsində kritik zəiflikdir. Autentifikasiya tələb etmədən PHP kodu inyeksiyasına imkan verir (CWE-94) – eval() funksiyası ilə işlənən xüsusi PHP handler vasitəsilə uzaqdan kod icrası mümkündür. Dərhal 2.4.3.2 və ya daha yuxarı versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-94
FAQ1
Which versions of the Balbooa Forms extension for Joomla are affected by CVE-2026-67364?
This critical vulnerability affects versions of the Balbooa Forms extension prior to 2.4.3.2. An immediate update to version 2.4.3.2 or later is required to ensure security.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.