CVE-2026-56291
KEV Critical · CVSS 9.8Balbooa Forms (Joomla extension) — Unauthenticated arbitrary file upload leading to Remote Code Execution (RCE)
- CVSS
- 9.8
- nvd
- EPSS
- 76.1%
- 99th pct
- KEV
- Listed
- 2026-07-10
- Class
- other
- CWE-434
Description
Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
Search profile — drives PoC discovery
Symbols com_balbooabalbooa_formsfile_uploaduploadexecutablephpJoomlaunauthenticated
Keywords CVE-2026-56291Balbooa FormsJoomla file upload RCEunauthenticated file upload JoomlaBalbooa Forms exploitCWE-434 Joomlaarbitrary file upload BalbooaBalbooa Forms PoCBalbooa Forms RCE
Versions: <UNKNOWN>
Ranked PoCs (1) — best first
Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.
- ★ 0
Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.
References
Status: enriched · ingested 2026-07-10T18:00:26.000Z · profiled 2026-07-10T18:30:26.000Z