Balbooa

Forms

8 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.37%
  • Veröffentlicht 29.09.2026 17:17:06
  • Zuletzt bearbeitet 06.10.2026 16:47:57

Joomla Extension - balbooa.com - Unauthenticated path traversal exfiltrates local files through auto-reply attachments in Balbooa Forms < 2.4.3.4 - Balbooa Forms accepts upload-field state as Guest-controlled JSON during public form submission. For e...

  • EPSS 0.32%
  • Veröffentlicht 29.09.2026 17:17:06
  • Zuletzt bearbeitet 06.10.2026 16:48:10

Joomla Extension - balbooa.com - Unauthenticated RCE via field shortcode injection in Balbooa Forms < 2.4.3.4 - Balbooa Forms supports administrator-defined PHP code which runs after a public form submission. The feature also supports form-field shor...

  • EPSS 0.37%
  • Veröffentlicht 29.09.2026 17:17:05
  • Zuletzt bearbeitet 06.10.2026 16:47:15

Joomla Extension - balbooa.com - File meta data tampering in Balbooa Forms < 2.4.3.4 - The final form submission processes JSON arrays per upload field, checking only that IDs are numeric. Client-supplied filenames and display names are trusted direc...

  • EPSS 0.32%
  • Veröffentlicht 29.09.2026 17:17:05
  • Zuletzt bearbeitet 06.10.2026 16:47:37

Joomla Extension - balbooa.com - Unauthenticated upload filename stored XSS in Balbooa Forms < 2.4.3.4 - The public form upload endpoint validates the uploaded file's extension and detected MIME type, but stores the attacker-supplied original multipa...

  • EPSS 0.3%
  • Veröffentlicht 29.09.2026 17:17:04
  • Zuletzt bearbeitet 06.10.2026 18:13:15

Joomla Extension - balbooa.com - Unauthorized Deletion of Attachments in Balbooa Forms < 2.4.3.4 - The public removeTmpAttachment action accepts an integer attachment ID and deletes the matching database row and file. The controller verifies a Joomla...

  • EPSS 0.32%
  • Veröffentlicht 19.08.2026 13:17:50
  • Zuletzt bearbeitet 26.08.2026 16:35:20

Joomla Extension - balbooa.com - Pre-auth Payment Amount Tampering in Balbooa Forms < 2.4.3.2 - The stripeCharges and payAuthorize endpoints accept the charge total from a client-controlled request parameter and forward it to the payment gateway with...

  • EPSS 0.29%
  • Veröffentlicht 19.08.2026 13:17:50
  • Zuletzt bearbeitet 29.09.2026 17:17:09

Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 - The form's optional custom-PHP post-submission handler is executed via eval(). The [URL parameter = X] shortcode is substituted with the raw, unescaped value of...

  • EPSS 0.46%
  • Veröffentlicht 28.07.2026 10:27:16
  • Zuletzt bearbeitet 28.07.2026 16:17:16

Joomla Extension - balbooa.com - Unauthenticated remote code execution in Balbooa Forms < 2.4.3 - An insecure form processing logic allowed code execution for forms that include the signature field type.