SecAlerts
b

balbooa

Security Risk Profile

60
/100
high

Security Risk Score

Comprehensive risk assessment based on 25 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from June 14, 2018 to present

25
Total CVEs
17
Critical+High
2
Exploited
17
Unpatched

Threat Assessment

Avg CVSS
8.3
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
17
Critical/High
Risk Level
60/100
high
⚠️ 2 Active Exploits⚡ 1 Zero-Days🆕 2Fresh (<7d)📈 7 in Last 30 Days

Severity Distribution

Critical
10
High
7
Medium
7
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
0

Age Distribution

Common Weaknesses (CWE)

1
Path Traversal
5
2
CSRF
4
3
XSS
4
4
SQL Injection
3
5
Code Injection
2

Most Affected Products

1. Balbooa Gridbox Joomla\!12
2. Balbooa Balbooa Forms6
3. Balbooa Forms Joomla\!6
4. balbooa.com Gridbox5
5. balbooa.com/Gridbox4

Recent Vulnerabilities

See more →
CVE-2026-102783
CVSS 6.3medium

Joomla Extension - balbooa.com - Path Traversal in image preview Gridbox < 2.20.4.0

Oct 8, 2026🔧 No Patch
CVE-2026-102784
CVSS 8.7high

Joomla Extension - balbooa.com - CSRF in language installation feature Gridbox < 2.20.4.0

Oct 8, 2026🔧 No Patch
CVE-2026-102424
CVSS 8.9high

Joomla Extension - balbooa.com - Unauthenticated path traversal exfiltrates local files through auto-reply attachments in Balbooa Forms < 2.4.3.4

Sep 29, 2026🔧 No Patch
CVE-2026-102425
CVSS 9.5critical

Joomla Extension - balbooa.com - Unauthenticated RCE via field shortcode injection in Balbooa Forms < 2.4.3.4

Sep 29, 2026🔧 No Patch
CVE-2026-101126
CVSS 6.9medium

Joomla Extension - balbooa.com - File meta data tampering in Balbooa Forms < 2.4.3.4

Sep 29, 2026🔧 No Patch
CVE-2026-101112
CVSS 6.9medium

Joomla Extension - balbooa.com - Unauthorized Deletion of Attachments in Balbooa Forms < 2.4.3.4

Sep 29, 2026🔧 No Patch
CVE-2026-101127
CVSS 8.6high

Joomla Extension - balbooa.com - Unauthenticated upload filename stored XSS in Balbooa Forms < 2.4.3.4

Sep 29, 2026🔧 No Patch
CVE-2026-67364
CVSS 10.0critical

Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2

Aug 19, 2026🔧 No Patch
CVE-2026-65947
CVSS 7.3high

Joomla Extension - balbooa.com - Various CSRF vectors in the admin interface in Gridbox < 2.20.2

Jul 29, 2026🔧 No Patch
CVE-2026-65888
CVSS 10.0critical

Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2

Jul 29, 2026🔧 No Patch

Monitor balbooa in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.