Description
Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
Published: 2026-07-09
Score: 10 Critical
EPSS: 76.1% High
KEV: Yes
Impact: n/a
Action: n/a
AI Analysis

Impact

The Balbooa Forms extension for Joomla is vulnerable to an unauthenticated arbitrary file upload flaw that permits attackers to upload executable files. Successfully uploaded executables can be executed, granting full control over the affected Joomla installation. This flaw is classified as a critical Remote Code Execution weakness, represented by CWE-434.

Affected Systems

All instances of the Balbooa Forms extension for Joomla with a version earlier than 2.4.1 are affected. The vulnerability applies to any website that has deployed these legacy versions of the extension and has not applied the latest update from balbooa.com.

Risk and Exploitability

The CVSS score of 10 indicates maximum severity. The EPSS score of 76% indicates a high probability of exploitation; however, the ability to upload arbitrary files without authentication means attackers can still exploit it if they have sufficient motivation, especially against exposed web servers. The vulnerability is listed in CISA’s KEV catalog, highlighting that it is actively exploited. Attackers can exploit the flaw without needing to authenticate, making it easily accessible to the general threat landscape.

Generated by OpenCVE AI on July 28, 2026 at 08:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Balbooa Forms extension to version 2.4.1 or later, which removes the unauthenticated upload functionality.
  • If an upgrade is not immediately possible, disable the extension or remove its upload directory to block file submissions.
  • Configure the web server to restrict file system permissions on upload directories, ensuring that uploaded files cannot be executed by the web application process.

Generated by OpenCVE AI on July 28, 2026 at 08:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Description The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE. Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

Fri, 10 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
References
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Metrics kev

{'dateAdded': '2026-07-10T00:00:00+00:00', 'dueDate': '2026-07-13T00:00:00+00:00'}


Fri, 10 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Balbooa.com
Balbooa.com balbooa.com Balbooa Forms Extension For Joomla
Vendors & Products Balbooa.com
Balbooa.com balbooa.com Balbooa Forms Extension For Joomla

Thu, 09 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Description The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
Title Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1
Weaknesses CWE-434
References
Metrics cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/AU:Y/U:Red'}


Subscriptions

Balbooa.com Balbooa.com Balbooa Forms Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-07-23T14:55:16.620Z

Reserved: 2026-06-20T11:57:32.752Z

Link: CVE-2026-56291

cve-icon Vulnrichment

Updated: 2026-07-09T13:48:51.218Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-28T09:00:06Z

Weaknesses
  • CWE-434

    Unrestricted Upload of File with Dangerous Type