Vulnary
← back to the feed
Critical· 10official fix available

CVE-2026-65880

A Joomla extension called Balbooa Forms is vulnerable to unauthenticated remote code execution. The flaw allows attackers to run arbitrary code by submitting a form that includes the signature field type. The vulnerability exists in all versions older than 2.4.3.

publishedJul 28, 2026
last modifiedJul 28, 2026
sourcesNVD
severity · cvss
10
critical · how bad it is
exploitation · epss
<1%
37th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Aug 27, 2026

An official fix is available, so this entry is kept for 30 days and then removed automatically.

01

Who is affected

Joomla sites that use the Balbooa Forms extension version 2.4.2 or earlier. Typical users are Joomla site administrators who have installed this extension.

02

Real-world impact

An attacker could run any code on the server, potentially taking full control of the website, stealing data, or using it for further attacks.

03

Why this severity

The CVSS score of 10 reflects that the vulnerability can be exploited remotely without authentication, with no user interaction, and gives the attacker full control over the system. The high impact on confidentiality, integrity, and availability, combined with low attack complexity, results in a critical rating.

04

What to do about it

official fix available
recommended steps
  1. 01Upgrade the Balbooa Forms extension to version 2.4.3 or later.
  2. 02Verify that the extension has been updated.

NVD description

05

Timeline

  1. Jul 28, 2026 · 2d ago
    Published
    Disclosed and added to the National Vulnerability Database.
  2. Jul 28, 2026 · 2d ago
    Official fix available
    A vendor patch or mitigation now exists — see the remediation steps above.
06

How it’s attacked

Attack vectorNetwork (remote)
Attack complexityLow
Attack requirementsNone
Privileges requiredNone
User interactionNone needed
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
07

References & advisories

(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →