Balbooa
6 articles tagged Balbooa, newest first.

Gridbox 2.20.4.0 Fixes a Language Install CSRF and an Image Path Check
Gridbox 2.20.4.0 fixes a CSRF flaw in language installation and tightens image preview path checks. Every Joomla site on 2.20.3.1 or older should update.

Balbooa Forms 2.4.3.4 Fixes Five Security Issues
Balbooa Forms 2.4.3.4 fixes five CVEs in the Joomla form builder, led by a 9.5 unauthenticated RCE. Every version below 2.4.3.4 is affected. Update now.

Blind SQL Injection in Gridbox's Blog Author
Gridbox 2.20.3.1 fixes an unauthenticated blind SQL injection in the blog author parameter that can read a Joomla site's whole database. Update now.

Another 23 Critical Security Vulnerabilities in Gridbox for Joomla
Balbooa asked mySites.guru to audit Gridbox for Joomla. We found 23 vulnerabilities, including a pre-auth RCE, some exploited already. Fixed in 2.20.2.

Gridbox for Joomla: One Cookie and You Are a Super User
A critical unauthenticated authentication bypass in Gridbox for Joomla let anyone become a Super User by setting a single cookie. Fixed in 2.20.1. Update now.

Balbooa Forms Fixes an Unauthenticated File Upload RCE
CVE-2026-56291: unauthenticated file upload RCE in Balbooa Forms (com_baforms) for Joomla, fixed in 2.4.1. More security releases followed: update to 2.4.3.4.