Stored Cross-Site Scripting Vulnerability in Gridbox by Balbooa
CVE-2026-66490

6.1MEDIUM

Key Information:

Vendor
CVE Published:
29 July 2026

What is CVE-2026-66490?

A stored cross-site scripting vulnerability has been identified in the Gridbox Joomla extension by Balbooa. This flaw allows attackers to inject malicious scripts that can be executed on a user's browser through a comment avatar feature. Affected versions prior to 2.20.2 are vulnerable to exploitation, which could lead to unauthorized access to sensitive user data and further malicious activities. Users are advised to upgrade to the latest version and review their security practices to mitigate risks.

Affected Version(s)

Gridbox extension for Joomla 1.0.0-2.20.1

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Phil Taylor, mysites.guru
.