Stored XSS Vulnerability in Balbooa Forms Joomla Extension
CVE-2026-101127
8.6HIGH
What is CVE-2026-101127?
The Balbooa Forms Joomla extension has a vulnerability wherein it allows the unauthenticated upload of file names that are stored verbatim. This issue arises because the extension validates the file's extension and MIME type but fails to sanitize the original filename uploaded by an attacker. Consequently, this filename is directly incorporated into the HTML used by administrators when they access form submissions. This can lead to the execution of malicious scripts in the context of the administrator, potentially compromising the web application.
Affected Version(s)
Balbooa Forms extension for Joomla 1.0.0-2.4.3.3
