Stored XSS Vulnerability in Balbooa Forms Joomla Extension
CVE-2026-101127

8.6HIGH

Key Information:

Vendor
CVE Published:
29 September 2026

What is CVE-2026-101127?

The Balbooa Forms Joomla extension has a vulnerability wherein it allows the unauthenticated upload of file names that are stored verbatim. This issue arises because the extension validates the file's extension and MIME type but fails to sanitize the original filename uploaded by an attacker. Consequently, this filename is directly incorporated into the HTML used by administrators when they access form submissions. This can lead to the execution of malicious scripts in the context of the administrator, potentially compromising the web application.

Affected Version(s)

Balbooa Forms extension for Joomla 1.0.0-2.4.3.3

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Łukasz Rybak
.