CVE-2026-66488: Joomla Extension - balbooa.com - Payment bypass in Gridbox < 2.20.2
Published Jul 29, 2026
·Updated
Joomla Extension - balbooa.com - Payment bypass in Gridbox < 2.20.2
Affected Software
2 affected components
balbooa.com Gridbox<2.20.2
Balbooa Gridbox Joomla\!<2.20.2
Event History
Jul 29, 2026
CVE Published
via MITRE·01:55 PM
Data Sourced
via MITRE·01:55 PM
Description
Data Sourced
via NVD·02:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-66488?
The severity of CVE-2026-66488 is medium with a CVSS score of 5.3.
2
How do I fix CVE-2026-66488?
To fix CVE-2026-66488, update the Gridbox extension to version 2.20.2 or later.
3
What vulnerability does CVE-2026-66488 address?
CVE-2026-66488 addresses a payment bypass issue in the Gridbox Joomla extension.
4
What versions are affected by CVE-2026-66488?
CVE-2026-66488 affects all versions of Gridbox before 2.20.2.
5
What impact could CVE-2026-66488 have on my site?
CVE-2026-66488 could allow unauthorized payment processing, leading to potential financial losses.