CSRF Vulnerability in Joomla Extension by Balbooa
CVE-2026-102784

8.7HIGH

Key Information:

Vendor
CVE Published:
8 October 2026

What is CVE-2026-102784?

The Joomla extension Gridbox by Balbooa is susceptible to a Cross-Site Request Forgery (CSRF) vulnerability in its language installation feature. In versions prior to 2.20.4.0, the PagesController allows a GET request to execute the addLanguage action without validating the session token, which should only be verified during POST requests. This oversight enables attackers to exploit the action without proper token checks, exposing users to unauthorized changes without their intent. Ensuring your Gridbox installation is updated is vital to maintaining robust security.

Affected Version(s)

Gridbox extension for Joomla 1.0.0-2.20.3.1

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Sergiy Tryzhychynskyi
.