Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 29 Jul 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Balbooa.com
Balbooa.com gridbox Extension For Joomla |
|
| Vendors & Products |
Balbooa.com
Balbooa.com gridbox Extension For Joomla |
Wed, 29 Jul 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 29 Jul 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 29 Jul 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 - File upload methods allows authenticated attackers to upload arbitrary files. Turns into an authenticated RCE if combined with CVE-2026-65884 as the required account can be created by the attacker. | |
| Title | Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 | |
| Weaknesses | CWE-434 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Joomla
Published:
Updated: 2026-07-29T13:53:59.859Z
Reserved: 2026-07-23T09:17:01.409Z
Link: CVE-2026-65885
Updated: 2026-07-29T12:41:12.708Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-29T15:00:03Z
-
CWE-434
Unrestricted Upload of File with Dangerous Type