CVE-2026-66490: Joomla Extension - balbooa.com - Stored cross-site scripting via a comment avatar in Gridbox < 2.20.2
Published Jul 29, 2026
·Updated
Joomla Extension - balbooa.com - Stored cross-site scripting via a comment avatar in Gridbox < 2.20.2
Affected Software
2 affected components
balbooa.com Gridbox<2.20.2
Balbooa Gridbox Joomla\!<2.20.2
Event History
Jul 29, 2026
CVE Published
via MITRE·01:54 PM
Data Sourced
via MITRE·01:54 PM
DescriptionWeakness
Data Sourced
via NVD·02:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-66490?
The severity of CVE-2026-66490 is classified as medium with a score of 6.1.
2
What type of vulnerability is CVE-2026-66490?
CVE-2026-66490 is categorized as a stored cross-site scripting (XSS) vulnerability.
3
How do I fix CVE-2026-66490?
To fix CVE-2026-66490, upgrade the Gridbox extension to version 2.20.2 or later.
4
What software is affected by CVE-2026-66490?
CVE-2026-66490 affects the Gridbox extension developed by balbooa.com.
5
When was CVE-2026-66490 published?
CVE-2026-66490 was published on July 29, 2026.