PatchSiren

Balbooa CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Balbooa CVE published 2026-07-29

CVE-2026-65947

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-29T15:16:29.500Z and has not been modified since then. The Gridbox extension for Joomla is vulnerable to Cross-Site Request Forgery (CSRF) attacks in the admin interface, affecting Gridbox versions prior to 2.20.2. This vulnerability allows attackers to perform unauthorized actions on behalf of auth [truncated]

CRITICAL Balbooa CVE published 2026-07-29

CVE-2026-65886

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-29T15:16:28.467Z and has not been modified since then. The Gridbox extension for Joomla! has a critical vulnerability allowing unauthenticated attackers to view arbitrary files due to a flaw in the photo viewer feature. This vulnerability has a CVSS score of 9.2 and is considered CRITICAL. The affec [truncated]

MEDIUM Balbooa CVE published 2026-07-29

CVE-2026-66490

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-29T14:16:34.373Z and has not been modified since then. The Gridbox Joomla Extension is vulnerable to stored cross-site scripting via a comment avatar in versions < 2.20.2. This vulnerability has a CVSS score of 6.1 and a CVSS severity of MEDIUM. Affected product context includes Joomla Extension use [truncated]

MEDIUM Balbooa CVE published 2026-07-29

CVE-2026-66488

The CVE-2026-66488 vulnerability is a Payment bypass issue in the Gridbox Joomla Extension versions less than 2.20.2. This vulnerability has a CVSS score of 5.3 and is classified under CWE-285. It allows for unauthorized modification of payment information. The affected product is used for payment processing, and the vulnerability can lead to potential payment bypass attacks. To address this vulnerability [truncated]

CRITICAL Balbooa CVE published 2026-07-29

CVE-2026-65890

CVE-2026-65890 is a critical vulnerability in the Gridbox Joomla Extension version less than 2.20.2. This vulnerability allows unauthenticated SQL injection attacks through multiple vectors, potentially leading to unauthorized access and data breaches. The CVE record was published on 2026-07-29T14:16:33.883Z. Affected organizations should prioritize patching to prevent exploitation. The vulnerability is c [truncated]

HIGH Balbooa CVE published 2026-05-10

CVE-2021-47930

CVE-2021-47930 is a high-severity SQL injection issue affecting Balbooa Joomla Forms Builder 2.0.6. According to the supplied description, an unauthenticated attacker can send crafted POST requests to the com_baforms component and supply malicious JSON in the 'id' field to execute arbitrary SQL queries and extract sensitive database information. Because no authentication is required and the attack surface [truncated]