CVE-2026-65888
Critical · CVSS 9.8- CVSS
- 9.8
- nvd
- EPSS
- 0.25%
- 16th pct
- KEV
- No
- Class
- other
- CWE-284, NVD-CWE-noinfo
Description
Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2 - The socialLogin method allows actors to login as any given user on the target site.
References
Status: profiled · ingested 2026-08-05T18:00:56.000Z