CVE-2026-65880: Balbooa.com Balbooa Forms Component For Joomla
Critical severity, CVSS 10.0. EPSS: 0.8% chance of exploitation in the next 30 days.
Joomla Extension - balbooa.com - Unauthenticated remote code execution in Balbooa Forms < 2.4.3 - An insecure form processing logic allowed code execution for forms that include the signature field type.
Affected products
- Balbooa.com Balbooa Forms Component For Joomla: version 1.0.0-2.4.2.1 only
Published 2026-07-28. Last modified 2026-07-28.