Joomla Extension - balbooa.com - Unauthorized Deletion of Attachments in Balbooa Forms < 2.4.3.4 - The public removeTmpAttachment action accepts an integer attachment ID and deletes the matching database row and file. The controller verifies a Joomla session t
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| balbooa.com | Balbooa Forms extension for Joomla | 1.0.0-2.4.3.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-102425 | 9.5 CRITICAL | Joomla Extension - balbooa.com - Unauthenticated RCE via field shortcode injection in Balb |
| CVE-2026-102424 | 8.9 HIGH | Joomla Extension - balbooa.com - Unauthenticated path traversal exfiltrates local files th |
| CVE-2026-101127 | 8.6 HIGH | Joomla Extension - balbooa.com - Unauthenticated upload filename stored XSS in Balbooa For |
| CVE-2026-101126 | 6.9 MEDIUM | Joomla Extension - balbooa.com - File meta data tampering in Balbooa Forms < 2.4.3.4 |
No comments yet