Security Advisory

CVE-2026-56291

9.8
CRITICAL

Vulnerability Description

Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
Published Date July 9, 2026
Official Source NIST NVD Advisory