Description
Joomla Extension - balbooa.com - Unauthenticated RCE via field shortcode injection in Balbooa Forms < 2.4.3.4 - Balbooa Forms supports administrator-defined PHP code which runs after a public form submission. The feature also supports form-field shortcodes inside that PHP. Before calling `eval()`, the component replaces each shortcode with the raw value submitted by the visitor, leading to an RCE vector. A public form must use the product's optional PHP-after-submission action and interpolate an attacker-controlled field shortcode inside a double-quoted PHP string to be vulnerable.
Published: 2026-09-29
Score: 9.5 Critical
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Balbooa Forms extension for Joomla allows administrators to define custom PHP code that runs after a form submission. The extension replaces each form-field shortcode with the raw data submitted by a visitor before executing eval(). An attacker can inject a shortcode that expands into malicious PHP inside a double‑quoted string, enabling unauthenticated remote code execution. This fault is a classic code injection vulnerability (CWE‑94).

Affected Systems

The balbooa.com Balbooa Forms extension for Joomla, any version earlier than 2.4.3.4, is affected.

Risk and Exploitability

The CVSS score of 9.5 reflects this high‑severity flaw. No EPSS value is available, so the exact exploitation probability cannot be quantified, and the vulnerability is not listed in the CISA KEV catalog. An attacker only needs a publicly accessible form that uses the PHP‑after‑submission action and contains a vulnerable shortcode; because the injected code runs under the web server’s privileges, successful exploitation could lead to complete compromise of the web application.

Generated by OpenCVE AI on September 30, 2026 at 00:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Balbooa Forms to version 2.4.3.4 or later
  • Disable the PHP‑after‑submission action unless it is absolutely required, or restrict its use to authenticated users
  • Inspect all forms for shortcode use and eliminate any attacker‑controllable fields

Generated by OpenCVE AI on September 30, 2026 at 00:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
Link Providers
https://www.balbooa.com/ cve-icon cve-icon
History

Tue, 29 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
Description Joomla Extension - balbooa.com - Unauthenticated RCE via field shortcode injection in Balbooa Forms < 2.4.3.4 - Balbooa Forms supports administrator-defined PHP code which runs after a public form submission. The feature also supports form-field shortcodes inside that PHP. Before calling `eval()`, the component replaces each shortcode with the raw value submitted by the visitor, leading to an RCE vector. A public form must use the product's optional PHP-after-submission action and interpolate an attacker-controlled field shortcode inside a double-quoted PHP string to be vulnerable.
Title Joomla Extension - balbooa.com - Unauthenticated RCE via field shortcode injection in Balbooa Forms < 2.4.3.4
Weaknesses CWE-94
References
Metrics cvssV4_0

{'score': 9.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-09-29T17:04:35.280Z

Reserved: 2026-09-29T04:38:08.434Z

Link: CVE-2026-102425

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-29T17:17:06.210

Modified: 2026-09-29T21:39:02.570

Link: CVE-2026-102425

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T00:30:17Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')