Balbooa

Gridbox

13 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.1%
  • Veröffentlicht 29.07.2026 14:00:50
  • Zuletzt bearbeitet 05.08.2026 17:23:43

Joomla Extension - balbooa.com - Various CSRF vectors in the admin interface in Gridbox < 2.20.2

  • EPSS 0.28%
  • Veröffentlicht 29.07.2026 13:59:27
  • Zuletzt bearbeitet 05.08.2026 17:23:55

Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2 - The socialLogin method allows actors to login as any given user on the target site.

  • EPSS 0.28%
  • Veröffentlicht 29.07.2026 13:58:23
  • Zuletzt bearbeitet 05.08.2026 17:24:03

Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2 - The resetPassword method allows actors to reset any user password, allowing to login and act as these users - excluding super admins.

  • EPSS 0.36%
  • Veröffentlicht 29.07.2026 13:58:16
  • Zuletzt bearbeitet 05.08.2026 17:24:10

Joomla Extension - balbooa.com - Unauthenticated arbitrary file read in Gridbox < 2.20.2 - The photo viewer allows unauthenticated attackers to view arbitrary files.

  • EPSS 0.28%
  • Veröffentlicht 29.07.2026 13:56:21
  • Zuletzt bearbeitet 05.08.2026 17:24:46

Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 - Multiple SQLi vectors allow unauthenticated actors to inject SQL in queries.

  • EPSS 0.15%
  • Veröffentlicht 29.07.2026 13:55:28
  • Zuletzt bearbeitet 05.08.2026 17:24:29

Joomla Extension - balbooa.com - Various unauthenticated file system disclosure in Gridbox < 2.20.2

  • EPSS 0.15%
  • Veröffentlicht 29.07.2026 13:55:19
  • Zuletzt bearbeitet 05.08.2026 17:24:36

Joomla Extension - balbooa.com - Payment bypass in Gridbox < 2.20.2

  • EPSS 0.28%
  • Veröffentlicht 29.07.2026 13:54:52
  • Zuletzt bearbeitet 05.08.2026 17:24:52

Joomla Extension - balbooa.com - Unauthenticated recursive directory deletion < 2.20.2 - The generateNewApp method allows actors to recursively delete directories.

  • EPSS 0.16%
  • Veröffentlicht 29.07.2026 13:54:24
  • Zuletzt bearbeitet 05.08.2026 17:24:22

Joomla Extension - balbooa.com - Stored cross-site scripting via a comment avatar in Gridbox < 2.20.2

  • EPSS 0.28%
  • Veröffentlicht 29.07.2026 12:09:08
  • Zuletzt bearbeitet 05.08.2026 18:37:44

Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The registration method allows users provided usergroup IDs, allowing unauthenticated actors to register new accounts with administrative permissions.