PatchSiren

Balbooa CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Balbooa CVE published 2026-05-10

CVE-2021-47930

CVE-2021-47930 is a high-severity SQL injection issue affecting Balbooa Joomla Forms Builder 2.0.6. According to the supplied description, an unauthenticated attacker can send crafted POST requests to the com_baforms component and supply malicious JSON in the 'id' field to execute arbitrary SQL queries and extract sensitive database information. Because no authentication is required and the attack surface [truncated]