Path Traversal Vulnerability in Balbooa Forms by Joomla Extension
CVE-2026-102424

8.9HIGH

Key Information:

Vendor
CVE Published:
29 September 2026

What is CVE-2026-102424?

The Balbooa Forms Joomla extension is susceptible to a path traversal vulnerability that allows unauthorized users to exfiltrate local files. When forms are submitted, the extension processes user-provided IDs and filenames without proper validation. This flaw permits attackers to craft requests that traverse the directory structure, potentially exposing sensitive configuration files. If the options for automatic replies and attaching files are enabled, the system can inadvertently send these sensitive files to the user’s email, thereby compromising the integrity of the website.

Affected Version(s)

Balbooa Forms extension for Joomla 1.0.0-2.4.3.3

References

CVSS V4

Score:
8.9
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Łukasz Rybak
.