Executive brief
Gridbox, a popular page-building tool for Joomla websites, contains a security flaw in its comment system. An attacker can use this flaw to inject malicious scripts into the avatar section of a comment, which will then run in the browser of anyone viewing that page. This could allow unauthorized individuals to steal session information or perform actions on behalf of other users, including site administrators.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in the Balbooa Gridbox extension for Joomla (com_gridbox) in versions prior to 2.20.2. The vulnerability is located in the comment avatar component, where user-supplied input is not properly neutralized before being rendered on the page (CWE-79). An unauthenticated or low-privileged attacker can upload or reference a malicious payload within a comment avatar. When other users, including administrators, view the affected page, the script executes in their browser context. This can lead to session hijacking, unauthorized administrative actions, or further exploitation of the site. The issue is resolved in version 2.20.2.
Affected products
- balbooa.com Gridbox extension for Joomla 1.0.0-2.20.1
Timeline
- 2026-07-20: patched: Initial fixes attempted in version 2.20.1
- 2026-07-29: disclosed: Full audit results and CVE assigned
- 2026-07-29: advisory: Final fix released in version 2.20.2