balbooa.com vulnerabilities
12 CVEs tracked
balbooa.com, specifically its Joomla extensions, features prominently in recent reporting with critical vulnerabilities. Key events involve unauthenticated Remote Code Execution (CVE-2026-65880) in Balbooa Forms, alongside SQL injection (CVE-2026-65890), payment bypass (CVE-2026-66488), and file system disclosure (CVE-2026-66489) in Gridbox. The reports highlight a dangerous privilege escalation (CVE-2026-65884) that enables unauthorized account creation with admin rights, which can be chained with an authenticated file upload (CVE-2026-65885) to achieve RCE. Defenders must immediately update Gridbox to version 2.20.2 and Balbooa Forms to 2.4.3, with a heightened focus on monitoring for unauthorized privileged account creation that could lead to a full RCE chain.
Azərbaycanca: balbooa.com, xüsusilə Joomla genişləndirilmələri ilə son hesabatlarda kritik zəifliklərlə bağlı önə çıxır. Əsas hadisələr Gridbox (CVE-2026-66488, CVE-2026-65885) və Balbooa Forms (CVE-2026-65880) məhsullarında autentifikasiya olmadan uzaqdan kod icrası(RCE), SQL injection və ödəniş yan keçmə hallarını əhatə edir. Hesabatlarda Gridbox-da imtiyaz artımı (CVE-2026-65884) və autentifikasiya olmadan fayl sistemi ifşası (CVE-2026-66489) kimi ciddi boşluqlar vurğulanır. Müdafiəçilər dərhal Gridbox-u 2.20.2, Forms-u isə 2.4.3 versiyalarına yeniləməli, Gridbox ilə əlaqəli RCE zənciri yarada biləcək icazəsiz hesab yaradılması (CVE-2026-65884) kimi risklərə qarşı xüsusilə ayıq olmalıdır.
This vendor's CVEs12
This hub is built from skopnix's own reporting on balbooa.com: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.