Description
Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
Published: 2026-07-09
Score: 10 Critical
EPSS: 76.1% High
KEV: Yes
Impact: n/a
Action: n/a
AI Analysis

Impact

The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full remote code execution. By uploading malicious files, an attacker can execute code on the server, gaining complete control over the Joomla installation. This flaw aligns with CWE-434 and is considered a critical vulnerability.

Affected Systems

All instances of the Balbooa Forms extension for Joomla with a version earlier than 2.4.1 are affected. The vulnerability applies to any website that has deployed these legacy versions of the extension and has not applied the latest update from balbooa.com.

Risk and Exploitability

The CVSS score of 10 indicates maximum severity. The EPSS score of 76% indicates a high probability of exploitation; however, the ability to upload arbitrary files without authentication means attackers can exploit it if they have sufficient motivation, especially against exposed web servers. The vulnerability is listed in CISA’s KEV catalog, highlighting that it is actively exploited. Attackers can exploit the flaw without needing to authenticate, making it easily accessible to the general threat landscape.

Generated by OpenCVE AI on August 3, 2026 at 04:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Balbooa Forms extension to version 2.4.1 or later, which removes the unauthenticated upload functionality.
  • If an upgrade is not immediately possible, disable the extension or remove its upload directory to block file submissions.
  • Configure the web server to restrict file system permissions on upload directories, ensuring that uploaded files cannot be executed by the web application process.

Generated by OpenCVE AI on August 3, 2026 at 04:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Description The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE. Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

Fri, 10 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
References
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Metrics kev

{'dateAdded': '2026-07-10T00:00:00+00:00', 'dueDate': '2026-07-13T00:00:00+00:00'}


Fri, 10 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Balbooa.com
Balbooa.com balbooa.com Balbooa Forms Extension For Joomla
Vendors & Products Balbooa.com
Balbooa.com balbooa.com Balbooa Forms Extension For Joomla

Thu, 09 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Description The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
Title Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1
Weaknesses CWE-434
References
Metrics cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/AU:Y/U:Red'}


Subscriptions

Balbooa Forms
Balbooa.com Balbooa.com Balbooa Forms Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-08-12T13:52:32.561Z

Reserved: 2026-06-20T11:57:32.752Z

Link: CVE-2026-56291

cve-icon Vulnrichment

Updated: 2026-07-09T13:48:51.218Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-09T11:16:40.990

Modified: 2026-07-24T13:30:37.550

Link: CVE-2026-56291

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T04:30:18Z

Weaknesses
  • CWE-434

    Unrestricted Upload of File with Dangerous Type