Pre-auth PHP Code Injection in Balbooa Forms by Joomla Extension
CVE-2026-67364

10CRITICAL

Key Information:

Vendor
CVE Published:
19 August 2026

What is CVE-2026-67364?

The Balbooa Forms extension for Joomla is susceptible to pre-authentication PHP code injection due to the insecure handling of custom-PHP post-submission handlers. When configured with an optional custom-PHP handler referencing an unescaped query parameter through the eval() function, an attacker can execute arbitrary PHP code on the server. Furthermore, the inadequate CSRF protection can be easily bypassed, leading to serious security implications. It's crucial for users to review their configuration and update to the latest version to mitigate these risks.

Affected Version(s)

Balbooa Forms extension for Joomla 1.0.0-2.4.3.1

References

CVSS V4

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Akinlabi Omoogun
.