CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-56291

KEV Critical · CVSS 9.8

Balbooa Forms (Joomla extension) — Unauthenticated arbitrary file upload leading to Remote Code Execution (RCE)

CVSS
9.8
nvd
EPSS
76.1%
99th pct
KEV
Listed
2026-07-10
Class
other
CWE-434

Description

Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

Search profile — drives PoC discovery

Symbols com_balbooabalbooa_formsfile_uploaduploadexecutablephpJoomlaunauthenticated
Keywords CVE-2026-56291Balbooa FormsJoomla file upload RCEunauthenticated file upload JoomlaBalbooa Forms exploitCWE-434 Joomlaarbitrary file upload BalbooaBalbooa Forms PoCBalbooa Forms RCE
Versions: <UNKNOWN>

Ranked PoCs (1) — best first

Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.

Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.

References

Status: enriched · ingested 2026-07-10T18:00:26.000Z · profiled 2026-07-10T18:30:26.000Z