OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-102425

CRITICAL · CVSS 10 EPSS 0.32%

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

The Balbooa Forms extension for Joomla versions prior to 2.4.3.4 is vulnerable to unauthenticated remote code execution (RCE) due to improper handling of field shortcode injections in PHP code executed after form submissions. This vulnerability allows attackers to inject malicious PHP code through user-controlled form fields, potentially compromising the server. Organizations using this extension should prioritize immediate patching to mitigate the risk of exploitation.

CVE
CVE-2026-102425
Severity
CRITICAL
CVSS
10
EPSS
0.32%

Original NVD Description

Joomla Extension - balbooa.com - Unauthenticated RCE via field shortcode injection in Balbooa Forms < 2.4.3.4 - Balbooa Forms supports administrator-defined PHP code which runs after a public form submission. The feature also supports form-field shortcodes inside that PHP. Before calling `eval()`, the component replaces each shortcode with the raw value submitted by the visitor, leading to an RCE vector. A public form must use the product's optional PHP-after-submission action and interpolate an attacker-controlled field shortcode inside a double-quoted PHP string to be vulnerable.

Related CVEs

Other vulnerabilities affecting the same vendor(s)