Balbooa gridbox是Balbooa公司开源的一个响应式Joomla页面构建器。 Balbooa Gridbox 2.20.2之前版本存在跨站脚本漏洞,该漏洞源于通过评论头像进行存储型跨站脚本攻击。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| balbooa.com | Gridbox extension for Joomla | 1.0.0-2.20.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| balbooa.com | Gridbox extension for Joomla | 1.0.0-2.20.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-65884 | 10.0 CRITICAL | Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 |
| CVE-2026-65888 | 10.0 CRITICAL | Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2 |
| CVE-2026-65887 | 10.0 CRITICAL | Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2. |
| CVE-2026-65885 | 9.4 CRITICAL | Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 |
| CVE-2026-65889 | 9.2 CRITICAL | Joomla Extension - balbooa.com - Unauthenticated recursive directory deletion in Gridbox < |
| CVE-2026-65890 | 9.2 CRITICAL | Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 |
| CVE-2026-65886 | 9.2 CRITICAL | Joomla Extension - balbooa.com - Unauthenticated arbitrary file read in Gridbox < 2.20.2 |
| CVE-2026-66489 | Joomla Extension - balbooa.com - Various unauthenticated file system disclosure in Gridbox | |
| CVE-2026-66488 | Joomla Extension - balbooa.com - Payment bypass in Gridbox < 2.20.2 | |
| CVE-2026-65947 | Joomla Extension - balbooa.com - Various CSRF vectors in the admin interface in Gridbox < |
No comments yet