CVE-2026-65890: Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2
Published Jul 29, 2026
·Updated
Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 - Multiple SQLi vectors allow unauthenticated actors to inject SQL in queries.
Affected Software
2 affected components
balbooa.com Gridbox<2.20.2
Balbooa Gridbox Joomla\!<2.20.2
Event History
Jul 29, 2026
CVE Published
via MITRE·01:56 PM
Data Sourced
via MITRE·01:56 PM
DescriptionWeakness
Data Sourced
via NVD·02:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-65890?
The severity of CVE-2026-65890 is critical with a CVSS score of 9.2.
2
How do I fix CVE-2026-65890?
You can fix CVE-2026-65890 by updating the Gridbox extension to version 2.20.2 or later.
3
What type of vulnerability is CVE-2026-65890?
CVE-2026-65890 is an unauthenticated SQL injection vulnerability.
4
Who is affected by CVE-2026-65890?
Users of the Gridbox extension for Joomla versions prior to 2.20.2 are affected by CVE-2026-65890.
5
What can an attacker do with CVE-2026-65890?
An attacker can leverage CVE-2026-65890 to inject SQL queries, potentially accessing sensitive data.