Joomla Extension - balbooa.com - File meta data tampering in Balbooa Forms < 2.4.3.4 - The final form submission processes JSON arrays per upload field, checking only that IDs are numeric. Client-supplied filenames and display names are trusted directly, intro
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| balbooa.com | Balbooa Forms extension for Joomla | 1.0.0-2.4.3.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-102425 | 9.5 CRITICAL | Joomla Extension - balbooa.com - Unauthenticated RCE via field shortcode injection in Balb |
| CVE-2026-102424 | 8.9 HIGH | Joomla Extension - balbooa.com - Unauthenticated path traversal exfiltrates local files th |
| CVE-2026-101127 | 8.6 HIGH | Joomla Extension - balbooa.com - Unauthenticated upload filename stored XSS in Balbooa For |
| CVE-2026-101112 | 6.9 MEDIUM | Joomla Extension - balbooa.com - Unauthorized Deletion of Attachments in Balbooa Forms < 2 |
No comments yet