Skip to main content
mySites.guru
J!Awards 2026mySites.guru is shortlisted for Your Favourite Tool in Your Joomla WorkflowVote by 11 OctoberHow to vote
CVE-2026-67363HighCVSS 7.7CVE published 19 August 2026Added to mySites.guru 18 August 2026

Balbooa Forms (com_baforms) 2.4.3 to below 2.4.3.2 - Unauthenticated PHP Code Injection (RCE, CVSS 10.0) and Unauthenticated Payment Amount Tampering

Balbooa Forms 2.4.3 and 2.4.3.1 are affected by two unauthenticated flaws fixed in 2.4.3.2 on 18 August 2026 and published as CVEs by the Joomla CNA on 19 August 2026. CVE-2026-67364 (CWE-94 / CWE-95, CVSS 4.0 base 10.0 Critical, CVSS 3.1 9.8, AV:N/AC:L/PR:N/UI:N) is a pre-auth PHP code injection: the form's optional custom-PHP post-submission handler is executed through eval(), and the [URL parameter = X] shortcode is substituted with the raw, unescaped value of a query parameter, so an unauthenticated visitor can inject arbitrary PHP that runs server-side. The CSRF token needed to reach the endpoint is itself disclosed anonymously through a separate task, so it provides no real protection. Exploitation requires the form to have a custom-PHP handler configured (a documented form-builder feature) that references that shortcode, and no reCAPTCHA on the submit button, so not every install on these versions is exploitable - but that precondition is an ordinary builder setting and cannot be ruled out remotely. CVE-2026-67363 (CWE-472 / CWE-602, CVSS 4.0 base 7.7 High) is pre-auth payment amount tampering: the stripeCharges and payAuthorize endpoints accept the charge total from a client-controlled request parameter and forward it to the payment gateway without recomputing it from the form's configured product prices, and neither endpoint enforces authentication or a CSRF check. An unauthenticated attacker can purchase any priced item for an arbitrary amount such as 0.01, and can additionally forge line items, quantities and shipping. Both CVE records give the affected range as 1.0.0 to 2.4.3.1. Balbooa originally presented 2.4.3.2 as routine hardening covering the Media Manager, path validation, payment validation, post-submission PHP scripts and signature image validation, and stated it was not related to any publicly disclosed vulnerability; these CVE records supersede that description, and two of those five areas are the ones above. This rule starts at 2.4.3 because it also absorbs the 2.4.3.1 hardening release of 31 July 2026, so a site on 2.4.3 is missing both sets of fixes. Update to Balbooa Forms 2.4.3.4 or later, which also includes the further security fixes released on 29 September 2026. If the site publishes a form with a custom-PHP post-submission handler, treat it as potentially compromised until checked: look for unfamiliar administrator accounts and for stray .php files under the upload folder (by default images/baforms/uploads/). If the site takes payments through a Balbooa form, reconcile recent Stripe or Authorize.Net transactions against the configured product prices. Everything up to and including 2.4.2.1 is covered by a separate rule carrying CVE-2026-65880 and CVE-2026-56291. Both of these CVEs are credited to Akinlabi Omoogun; neither was a mySites.guru finding.

Is my site affected?

Affected
Balbooa Forms from 2.4.3 up to but not including 2.4.3.2
Fixed in
2.4.3.2
What to do
Update Balbooa Forms to 2.4.3.2 for this flaw, or to 2.4.3.4 or later, which no rule we check matches.

How CVE-2026-67363 is scored

The base metrics as Joomla CNA published them, and what each one means for a site running an affected version. Threat and environmental metrics are left out: they describe a moment or a particular install rather than the flaw.

7.7 High

CVSS 4.0, scored by Joomla CNA
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:N

How it is reached

AV:N Attack vector
Network. Reachable across the internet
AC:L Attack complexity
Low. Nothing to work around, it just works
AT:N Attack requirements
None. Works against any affected install
PR:N Privileges required
None. No account needed
UI:N User interaction
None. Nobody has to be tricked into anything

What it does to the site

VC:N Confidentiality
None. Nothing can be read
VI:N Integrity
None. Nothing can be altered
VA:N Availability
None. The site stays up

What it does beyond the site

SC:N Confidentiality
None. Other systems keep their data
SI:H Integrity
High. Other systems can be altered
SA:N Availability
None. Other systems stay up

The rule below is rated Critical for the set of 2 CVEs it covers together, not for this record on its own.

Timeline

  1. 18 August 2026mySites.guru check added for Balbooa Forms (from 2.4.3 up to but not including 2.4.3.2)
  2. 19 August 2026CVE-2026-67363 record published by its CNA

Rule details

Other vulnerabilities in Balbooa Forms

Updating for CVE-2026-67363 alone can leave a site on a release another rule still matches. These are the other flaws we check for in the same extension.

Balbooa Forms

Latest safe version: 2.4.3.4

All 10 CVEs in Balbooa Forms

References

CVE-2026-67363 questions

Which versions are affected by CVE-2026-67363?
CVE-2026-67363 affects Balbooa Forms from 2.4.3 up to but not including 2.4.3.2. The fix is in 2.4.3.2.
How do I fix CVE-2026-67363?
Update Balbooa Forms to 2.4.3.2 for this flaw, or to 2.4.3.4 or later, which no rule we check matches. Then confirm the installed version on the Joomla administrator's Extensions: Manage screen.
How severe is CVE-2026-67363?
Joomla CNA scores it 7.7 (High) under CVSS 4.0. In plain terms: reachable across the internet, no account needed and nobody has to be tricked into anything.

Running an affected version on a site you manage?

A free audit tells you which of your Joomla and WordPress sites run an affected version, which are out of date, and which have not been backed up. No card required. If a site is already compromised, fix.mysites.guru is a single fixed fee per incident, usually resolved the same day.

This check is part of the mySites.guru Joomla vulnerability scanner, which reads every installed extension's version on each audit. Browse the rest of the Joomla vulnerability database.

Rules current as of 5 October 2026.