Balbooa Gridbox extension for Joomla是Balbooa公司的一款Joomla的Gridbox扩展插件。 Balbooa Gridbox extension for Joomla 2.20.2之前版本存在权限许可和访问控制问题漏洞,该漏洞源于注册方法允许用户提供用户组ID,可能导致未经身份验证的攻击者注册具有管理员权限的新账户,造成权限提升。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| balbooa.com | Gridbox extension for Joomla | 1.0.0-2.20.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| balbooa.com | Gridbox extension for Joomla | 1.0.0-2.20.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-65888 | 10.0 CRITICAL | Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2 |
| CVE-2026-65887 | 10.0 CRITICAL | Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2. |
| CVE-2026-65885 | 9.4 CRITICAL | Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 |
| CVE-2026-65889 | 9.2 CRITICAL | Joomla Extension - balbooa.com - Unauthenticated recursive directory deletion in Gridbox < |
| CVE-2026-65890 | 9.2 CRITICAL | Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 |
| CVE-2026-65886 | 9.2 CRITICAL | Joomla Extension - balbooa.com - Unauthenticated arbitrary file read in Gridbox < 2.20.2 |
| CVE-2026-66489 | Joomla Extension - balbooa.com - Various unauthenticated file system disclosure in Gridbox | |
| CVE-2026-66488 | Joomla Extension - balbooa.com - Payment bypass in Gridbox < 2.20.2 | |
| CVE-2026-66490 | Joomla Extension - balbooa.com - Stored cross-site scripting via a comment avatar in Gridb | |
| CVE-2026-65947 | Joomla Extension - balbooa.com - Various CSRF vectors in the admin interface in Gridbox < |
No comments yet