Executive brief
Gridbox, a popular website builder extension for the Joomla content management system, contains a security flaw in its file upload functionality. An authenticated user can upload malicious files to the server, which could lead to a complete takeover of the website. If combined with other known vulnerabilities that allow for unauthorized account creation, this could result in a total system compromise by an external attacker.
Technical details
An unrestricted file upload vulnerability (CWE-434) exists in the Balbooa Gridbox extension for Joomla in versions prior to 2.20.2. The file upload methods fail to properly validate file extensions or content, allowing an authenticated attacker with high privileges to upload arbitrary files, such as PHP scripts, to the web server. While the vulnerability requires authentication (PR:H), it can be escalated to a full Remote Code Execution (RCE) chain if combined with CVE-2026-65884, which may allow an attacker to create the necessary account. The issue is resolved in version 2.20.2.
Affected products
- balbooa.com Gridbox extension for Joomla (com_gridbox) 1.0.0-2.20.1
Timeline
- 2026-07-29: advisory: NVD publication date
- 2026-07-29: patched: Vendor released version 2.20.2 to address the issue