CVE-2026-56291: Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability
Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2026-07-10. EPSS: 14.9% chance of exploitation in the next 30 days.
Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
Affected products
- Balbooa Forms: before 2.4.1 (fixed in 2.4.1)
Published 2026-07-09. Last modified 2026-07-24.