File System Disclosure Vulnerability in Joomla Extension by Balbooa
CVE-2026-66489

5.3MEDIUM

Key Information:

Vendor
CVE Published:
29 July 2026

What is CVE-2026-66489?

The Gridbox extension for Joomla by Balbooa has a vulnerability that allows unauthenticated users to access sensitive files on the server. This flaw, present in versions prior to 2.20.2, can potentially lead to the unintended exposure of critical information. It is essential for users of this extension to upgrade to mitigate risks associated with unauthorized file access.

Affected Version(s)

Gridbox extension for Joomla 1.0.0-2.20.1

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Phil Taylor
.