Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-67364— Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2

Quick assessment

Affected
balbooa.com Balbooa Forms extension for Joomla
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Joomla 扩展 - balbooa.com - Balbooa Forms < 2.4.3.2 中存在预认证 PHP 代码注入漏洞 - CWE-94 / CWE-95 该表单的可选自定义 PHP 提交后处理程序通过 eval() 函数执行。[URL 参数 = X] 短代码被替换为查询参数的原始、未转义值,从而允许未经身份验证的攻击者注入可在服务器端执行的任意 PHP 代码。用于访问该端点所需的 CSRF 令牌本身可通过另一个独立任务匿名获取,因此并不能提供真正的防护。此漏洞的可利用性要求表单必须配置了自定义 P

CVSS 10.0 · Critical EPSS 0.29% · P22

Affected Version Matrix 1

VendorProduct Version RangeStatus
balbooa.com Balbooa Forms extension for Joomla 1.0.0-2.4.3.1 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-67364

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2
Source: CVE Program / CVE List V5
Vulnerability Description
Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 - CWE-94 / CWE-95 | CVSS 3.1: 9.8 Critical (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) The form's optional custom-PHP post-submission handler is executed via eval(). The [URL parameter = X] shortcode is substituted with the raw, unescaped value of a query parameter, letting an unauthenticated attacker inject arbitrary PHP that executes server-side. The CSRF token needed to reach the endpoint is itself disclosed anonymously via a separate task, so it provides no real protection. Exploitability requires the form to have a custom-PHP handler configured (a documented builder feature) referencing that shortcode, and no reCAPTCHA on the submit button.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Source: CVE Program / CVE List V5
Vulnerability Type
对生成代码的控制不恰当(代码注入)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
balbooa.com Balbooa Forms extension for Joomla 1.0.0-2.4.3.1 -

II. Public POCs for CVE-2026-67364

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-67364

登录查看更多情报信息。

Vendor Pages for CVE-2026-67364 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-67364

No comments yet


Leave a comment