Remote Code Execution Risk in Balbooa Forms by Joomla Extension
CVE-2026-102425
9.5CRITICAL
What is CVE-2026-102425?
The Balbooa Forms extension for Joomla has a vulnerability that allows unauthenticated remote code execution (RCE) due to improper handling of PHP code submission. This issue arises when the product supports administrator-defined PHP code that executes after a public form submission. By manipulating form-field shortcodes within a PHP string, an attacker can exploit this flaw, leading to the execution of arbitrary PHP code on the server. It is crucial for users of Balbooa Forms to ensure they update to the latest version to mitigate this risk.
Affected Version(s)
Balbooa Forms extension for Joomla 1.0.0-2.4.3.3
