Vulnerabilities
Vulnerable Software
Balbooa:  >> Gridbox  >> 2.20.1  Security Vulnerabilities
Joomla Extension - balbooa.com - Various CSRF vectors in the admin interface in Gridbox < 2.20.2
CVSS Score
7.3
EPSS Score
0.001
Published
2026-07-29
Joomla Extension - balbooa.com - Unauthenticated arbitrary file read in Gridbox < 2.20.2 - The photo viewer allows unauthenticated attackers to view arbitrary files.
CVSS Score
9.2
EPSS Score
0.004
Published
2026-07-29
Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2 - The resetPassword method allows actors to reset any user password, allowing to login and act as these users - excluding super admins.
CVSS Score
10.0
EPSS Score
0.003
Published
2026-07-29
Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2 - The socialLogin method allows actors to login as any given user on the target site.
CVSS Score
10.0
EPSS Score
0.003
Published
2026-07-29
Joomla Extension - balbooa.com - Payment bypass in Gridbox < 2.20.2
CVSS Score
5.3
EPSS Score
0.002
Published
2026-07-29
Joomla Extension - balbooa.com - Various unauthenticated file system disclosure in Gridbox < 2.20.2
CVSS Score
5.3
EPSS Score
0.002
Published
2026-07-29
Joomla Extension - balbooa.com - Stored cross-site scripting via a comment avatar in Gridbox < 2.20.2
CVSS Score
6.1
EPSS Score
0.002
Published
2026-07-29
Joomla Extension - balbooa.com - Unauthenticated recursive directory deletion < 2.20.2 - The generateNewApp method allows actors to recursively delete directories.
CVSS Score
9.2
EPSS Score
0.003
Published
2026-07-29
Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 - Multiple SQLi vectors allow unauthenticated actors to inject SQL in queries.
CVSS Score
9.2
EPSS Score
0.003
Published
2026-07-29
Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The registration method allows users provided usergroup IDs, allowing unauthenticated actors to register new accounts with administrative permissions.
CVSS Score
10.0
EPSS Score
0.003
Published
2026-07-29


Contact Us

Shodan ® - All rights reserved