SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-65890

CRITICAL · CVSS 9.8 EPSS 0.28%

Source: NVD + CISA KEV + EPSS · Published 2026-07-29 · Last synced 2026-08-28

CyberRota Analysis

AI-Generated

The Joomla Extension from balbooa.com, specifically versions prior to 2.20.2 of Gridbox, is vulnerable to unauthenticated SQL injection due to multiple exploitable vectors. This flaw allows attackers to manipulate SQL queries, potentially leading to unauthorized data access or modification. Joomla site administrators using affected versions should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-65890
Severity
CRITICAL
CVSS
9.8
EPSS
0.28%

Original NVD Description

Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 - Multiple SQLi vectors allow unauthenticated actors to inject SQL in queries.

Related CVEs

Other vulnerabilities affecting the same vendor(s)