Description
Joomla Extension - balbooa.com - Unauthenticated remote code execution in Balbooa Forms < 2.4.3 - An insecure form processing logic allowed code execution for forms that include the signature field type.
Published: 2026-07-28
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An insecure form processing logic in Balbooa Forms allows attackers to execute arbitrary code by submitting a form that contains the signature field type. This flaw is a code injection vulnerability that does not require authentication, enabling an attacker to execute commands on the host server with the web application’s privileges.

Affected Systems

The vulnerability affects the Joomla extension Balbooa Forms component provided by balbooa.com. Any installation using a version earlier than 2.4.3 is susceptible.

Risk and Exploitability

The CVSS score of 10 marks the flaw as critical, and the EPSS score of less than 1% indicates a low but non-zero probability of exploitation. Because the attacker does not need prior authentication and the threat is listed in the common weaknes enumeration as CWE-94, an exploit could lead to complete compromise of the affected Joomla site. The vulnerability is not currently listed in the CISA KEV catalog, but its severity warrants immediate attention.

Generated by OpenCVE AI on August 3, 2026 at 15:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Balbooa Forms to version 2.4.3 or later, ensuring the patch is applied to all sites that use the extension.
  • For sites unable to upgrade immediately, remove or disable the signature field type from any forms, and configure form processing to ignore this field.
  • Audit all existing form configurations and delete any signature fields or implement strict input validation to prevent code injection.

Generated by OpenCVE AI on August 3, 2026 at 15:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Fri, 07 Aug 2026 13:15:00 +0000

Type Values Removed Values Added
Title Joomla Extension - joomshaper.com - Unauthenticated remote code execution in Balbooa Forms < 2.4.3 Joomla Extension - balbooa.com - Unauthenticated remote code execution in Balbooa Forms < 2.4.3

Tue, 28 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Balbooa.com
Balbooa.com balbooa Forms Component For Joomla
Vendors & Products Balbooa.com
Balbooa.com balbooa Forms Component For Joomla

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Description Joomla Extension - balbooa.com - Unauthenticated remote code execution in Balbooa Forms < 2.4.3 - An insecure form processing logic allowed code execution for forms that include the signature field type.
Title Joomla Extension - joomshaper.com - Unauthenticated remote code execution in Balbooa Forms < 2.4.3
Weaknesses CWE-94
References
Metrics cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Balbooa.com Balbooa Forms Component For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-08-07T12:59:22.705Z

Reserved: 2026-07-23T09:17:01.409Z

Link: CVE-2026-65880

cve-icon Vulnrichment

Updated: 2026-07-28T12:19:56.154Z

cve-icon NVD

Status : Deferred

Published: 2026-07-28T11:17:04.233

Modified: 2026-07-28T16:17:16.127

Link: CVE-2026-65880

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T15:30:03Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')