Executive brief
Gridbox is a popular page builder and website creation tool for the Joomla content management system. A security vulnerability allows unauthorized individuals to perform database queries without a password, potentially leading to the theft of sensitive information such as user account details and password hashes. This could result in full site takeover, data breaches, and significant reputational damage for affected organizations.
Technical details
Multiple SQL injection (SQLi) vulnerabilities exist in the Balbooa Gridbox extension for Joomla (com_gridbox) prior to version 2.20.2. These flaws reside in several endpoints that fail to properly neutralize special elements in SQL commands (CWE-89). An unauthenticated remote attacker can exploit these vectors by sending specially crafted HTTP requests to the affected site. Successful exploitation allows for the extraction of sensitive data from the database, including Joomla user tables and password hashes. This vulnerability was part of a larger set of 23 critical flaws identified in the component, some of which are reportedly being exploited in the wild. Users should update to version 2.20.2 immediately.
Affected products
- balbooa.com Gridbox extension for Joomla 1.0.0-2.20.1
Timeline
- 2026-07-20: patched: Initial partial fix in version 2.20.1
- 2026-07-29: disclosed: Public disclosure of the vulnerability and CVE assignment
- 2026-07-29: patched: Final comprehensive fix released in version 2.20.2