Impact
The vulnerability allows authenticated users to upload arbitrary files through the Gridbox extension for Joomla. The upload process does not properly validate file types, causing the possibility of executing malicious code when combined with the related CVE-2026-65884; it is classified as CWE-434.
Affected Systems
The Gridbox extension from balbooa.com for Joomla is affected in versions earlier than 2.20.2. Sites that have installed these versions and grant upload permissions to administrators or editors are vulnerable.
Risk and Exploitability
The CVSS score of 9.4 signifies critical severity, and the EPSS score of less than 1% indicates a low but non‑zero probability of exploitation. Because the flaw requires authenticated access, an attacker who can create an account or compromise an existing one can upload malicious files, potentially leading to remote code execution. The vulnerability is not listed in CISA KEV, but its impact warrants immediate action.
OpenCVE Enrichment