Каталог CVE

Разработчик: balbooa.com

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Сбросить

Найдено: 16

Разработчик: balbooa.com
Критическая CVSS 10.0

CVE-2026-67364

Разработчикbalbooa.com

Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 - CWE-94 / CWE-95 | CVSS 3.1: 9.8 Critical (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) The form's optional custom-PHP post-submission handle…

19.08.2026 Требует внимания
Высокая CVSS 7.7

CVE-2026-67363

Разработчикbalbooa.com

Pre-auth Payment Amount Tampering in Balbooa Forms < 2.4.3.2 - The stripeCharges and payAuthorize endpoints accept the charge total from a client-controlled request parameter and forward it…

19.08.2026 Требует внимания
Высокая CVSS 7.3

CVE-2026-65947

РасширениеBalbooa Gridbox
Разработчикbalbooa.com

Various CSRF vectors in the admin interface in Gridbox < 2.20.2

29.07.2026 Требует внимания
Критическая CVSS 10.0

CVE-2026-65888

РасширениеBalbooa Gridbox
Разработчикbalbooa.com

Account takeover vulnerability in Gridbox < 2.20.2 - The socialLogin method allows actors to login as any given user on the target site.

29.07.2026 Требует внимания
Критическая CVSS 10.0

CVE-2026-65887

РасширениеBalbooa Gridbox
Разработчикbalbooa.com

Unauthenticated arbitrary password reset in Gridbox < 2.20.2 - The resetPassword method allows actors to reset any user password, allowing to login and act as these users - excluding super…

29.07.2026 Требует внимания
Критическая CVSS 9.2

CVE-2026-65886

РасширениеBalbooa Gridbox
Разработчикbalbooa.com

Unauthenticated arbitrary file read in Gridbox < 2.20.2 - The photo viewer allows unauthenticated attackers to view arbitrary files.

29.07.2026 Требует внимания
Средняя CVSS 6.1

CVE-2026-66490

РасширениеBalbooa Gridbox
Разработчикbalbooa.com

Stored cross-site scripting via a comment avatar in Gridbox < 2.20.2

29.07.2026 Активна
Критическая CVSS 9.2

CVE-2026-65890

РасширениеBalbooa Gridbox
Разработчикbalbooa.com

Unauthenticated SQL injection in Gridbox < 2.20.2 - Multiple SQLi vectors allow unauthenticated actors to inject SQL in queries.

29.07.2026 Требует внимания
Критическая CVSS 9.2

CVE-2026-65889

РасширениеBalbooa Gridbox
Разработчикbalbooa.com

Unauthenticated recursive directory deletion < 2.20.2 - The generateNewApp method allows actors to recursively delete directories.

29.07.2026 Требует внимания
Критическая CVSS 9.4

CVE-2026-65885

РасширениеBalbooa Gridbox
Разработчикbalbooa.com

Authenticated arbitrary file upload in Gridbox < 2.20.2 - File upload methods allows authenticated attackers to upload arbitrary files. Turns into an authenticated RCE if combined with CVE-…

29.07.2026 Требует внимания
Критическая CVSS 10.0

CVE-2026-65884

РасширениеBalbooa Gridbox
Разработчикbalbooa.com

Privilege Escalation in Gridbox < 2.20.2 - The registration method allows users provided usergroup IDs, allowing unauthenticated actors to register new accounts with administrative permissi…

29.07.2026 Требует внимания
Критическая CVSS 10.0

CVE-2026-65880

Разработчикbalbooa.com

Unauthenticated remote code execution in Balbooa Forms < 2.4.3 - An insecure form processing logic allowed code execution for forms that include the signature field type.

28.07.2026 Требует внимания
Критическая CVSS 9.4

CVE-2026-61425

Разработчикbalbooa.com

Authentication bypass in Gridbox < 1.6.0 - The Joomla extension Gridbox is vulnerable an authenticated bypass, potentially leading to full admin access.

20.07.2026 Требует внимания
Критическая CVSS 10.0

CVE-2026-56291

РасширениеBalbooa Forms
Разработчикbalbooa.com

Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executabl…

09.07.2026 Требует внимания