CVE-2026-65880
A Joomla extension called Balbooa Forms is vulnerable to unauthenticated remote code execution. The flaw allows attackers to run arbitrary code by submitting a form that includes the signature field type. The vulnerability exists in all versions older than 2.4.3.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Joomla sites that use the Balbooa Forms extension version 2.4.2 or earlier. Typical users are Joomla site administrators who have installed this extension.
Real-world impact
An attacker could run any code on the server, potentially taking full control of the website, stealing data, or using it for further attacks.
Why this severity
The CVSS score of 10 reflects that the vulnerability can be exploited remotely without authentication, with no user interaction, and gives the attacker full control over the system. The high impact on confidentiality, integrity, and availability, combined with low attack complexity, results in a critical rating.
What to do about it
- 01Upgrade the Balbooa Forms extension to version 2.4.3 or later.
- 02Verify that the extension has been updated.
NVD description
Timeline
- Jul 28, 2026 · 2d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 28, 2026 · 2d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.