CVE-2026-65885: Balbooa Gridbox
High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.
Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 - File upload methods allows authenticated attackers to upload arbitrary files. Turns into an authenticated RCE if combined with CVE-2026-65884 as the required account can be created by the attacker.
Affected products
- Balbooa Gridbox: before 2.20.2 (fixed in 2.20.2)
Published 2026-07-29. Last modified 2026-08-05.