CVE-2026-65880: Joomla Extension - balbooa.com - Unauthenticated remote code execution in Balbooa Forms < 2.4.3
Published Jul 28, 2026
·Updated
Joomla Extension - balbooa.com - Unauthenticated remote code execution in Balbooa Forms < 2.4.3 - An insecure form processing logic allowed code execution for forms that include the signature field type.
Affected Software
1 affected component
Joomla Extension - Balbooa Forms<2.4.3
Event History
Jul 28, 2026
CVE Published
via MITRE·10:27 AM
Data Sourced
via MITRE·10:27 AM
DescriptionWeakness
Data Sourced
via NVD·11:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-65880?
The severity of CVE-2026-65880 is critical with a CVSS score of 10.
2
What type of vulnerability is identified by CVE-2026-65880?
CVE-2026-65880 is an unauthenticated remote code execution vulnerability.
3
How do I fix CVE-2026-65880?
To fix CVE-2026-65880, upgrade Balbooa Forms to version 2.4.3 or later.
4
Which software is affected by CVE-2026-65880?
CVE-2026-65880 affects the Balbooa Forms Joomla extension from joomshaper.com and balbooa.com.
5
What causes the vulnerability in CVE-2026-65880?
The vulnerability in CVE-2026-65880 is caused by insecure form processing logic that allows code execution via a signature field.