Joomla Extension - balbooa.com - Unauthenticated upload filename stored XSS in Balbooa Forms < 2.4.3.4 - The public form upload endpoint validates the uploaded file's extension and detected MIME type, but stores the attacker-supplied original multipart filenam
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| balbooa.com | Balbooa Forms extension for Joomla | 1.0.0-2.4.3.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-102425 | 9.5 CRITICAL | Joomla Extension - balbooa.com - Unauthenticated RCE via field shortcode injection in Balb |
| CVE-2026-102424 | 8.9 HIGH | Joomla Extension - balbooa.com - Unauthenticated path traversal exfiltrates local files th |
| CVE-2026-101112 | 6.9 MEDIUM | Joomla Extension - balbooa.com - Unauthorized Deletion of Attachments in Balbooa Forms < 2 |
| CVE-2026-101126 | 6.9 MEDIUM | Joomla Extension - balbooa.com - File meta data tampering in Balbooa Forms < 2.4.3.4 |
No comments yet