VendorsBalbooagridboxany version
Vulnerabilities

Balbooa Gridbox any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

12CVEs
CVE-2026-65884
Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2
Published 2026-07-29 · Analyzed
10.0EPSS 0.005
CVE-2026-65887
Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2
Published 2026-07-29 · Analyzed
10.0EPSS 0.005
CVE-2026-65888
Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2
Published 2026-07-29 · Analyzed
10.0EPSS 0.005
CVE-2026-65890
Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2
Published 2026-07-29 · Analyzed
9.8EPSS 0.005
CVE-2026-65885
Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2
Published 2026-07-29 · Analyzed
9.4EPSS 0.005
CVE-2026-65886
Joomla Extension - balbooa.com - Unauthenticated arbitrary file read in Gridbox < 2.20.2
Published 2026-07-29 · Analyzed
9.2EPSS 0.006
CVE-2026-65889
Joomla Extension - balbooa.com - Unauthenticated recursive directory deletion in Gridbox < 2.20.2
Published 2026-07-29 · Analyzed
9.2EPSS 0.004
CVE-2026-65947
Joomla Extension - balbooa.com - Various CSRF vectors in the admin interface in Gridbox < 2.20.2
Published 2026-07-29 · Analyzed
7.3EPSS 0.002
CVE-2018-11690
The Balbooa Gridbox extension version 2.4.0 and previous versions for Joomla! is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability via a crafted URL to execute script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.
Published 2018-06-14 · Modified
6.1EPSS 0.335
CVE-2026-66490
Joomla Extension - balbooa.com - Stored cross-site scripting via a comment avatar in Gridbox < 2.20.2
Published 2026-07-29 · Analyzed
6.1EPSS 0.003
CVE-2026-66489
Joomla Extension - balbooa.com - Various unauthenticated file system disclosure in Gridbox < 2.20.2
Published 2026-07-29 · Analyzed
5.3EPSS 0.003
CVE-2026-66488
Joomla Extension - balbooa.com - Payment bypass in Gridbox < 2.20.2
Published 2026-07-29 · Analyzed
5.3EPSS 0.003