CyberICT

CVE-2026-56291

Balbooa · Published July 9, 2026

CVSS v3.1

CRITICAL
Patch availableGet patch

Description

The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

Affected Products

  • Forms < 2.4.1

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H