Executive brief
Balbooa Forms is a popular extension for the Joomla content management system used to create and manage website forms. A critical security flaw allows unauthorized individuals to upload malicious files to the web server without needing a password. This could allow an attacker to take complete control of the website, steal sensitive data, or disrupt business operations.
Technical details
The Balbooa Forms extension for Joomla is vulnerable to an unrestricted file upload (CWE-434). The flaw exists because the component fails to properly validate or restrict the types of files uploaded by users. An unauthenticated remote attacker can exploit this by sending a specially crafted request to upload executable scripts (such as PHP files) to the server. Once uploaded, these files can be executed to achieve full Remote Code Execution (RCE) with the privileges of the web server. The vulnerability is reportedly being exploited in the wild.
Affected products
- Balbooa.com Balbooa Forms extension for Joomla 1.0-2.4.0
Timeline
- 2026-07-09: advisory: CVE published by Joomla! Project and NVD
- 2026-07-10: disclosed: Public disclosure of the vulnerability details
- 2026-07-10: exploited: Reported as exploited in the wild