Pre-auth PHP Code Injection in Balbooa Forms by Joomla Extension
CVE-2026-67364
10CRITICAL
What is CVE-2026-67364?
The Balbooa Forms extension for Joomla is susceptible to pre-authentication PHP code injection due to the insecure handling of custom-PHP post-submission handlers. When configured with an optional custom-PHP handler referencing an unescaped query parameter through the eval() function, an attacker can execute arbitrary PHP code on the server. Furthermore, the inadequate CSRF protection can be easily bypassed, leading to serious security implications. It's crucial for users to review their configuration and update to the latest version to mitigate these risks.
Affected Version(s)
Balbooa Forms extension for Joomla 1.0.0-2.4.3.1
