← Back

Gridbox

gridbox

Vendor: Balbooa • 12 CVEs

CVEs (12)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Balbooa
1Gridbox
Aug 5, 2026
Jul 29, 2026
N/A· v4
7.3 HIGH· v3
N/A· v2
Joomla Extension - balbooa.com - Various CSRF vectors in the admin interface in Gridbox < 2.20.2
1Balbooa
1Gridbox
Aug 5, 2026
Jul 29, 2026
10.0 CRITICAL· v4
9.8 CRITICAL· v3
N/A· v2
Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2 - The socialLogin method allows actors to login as any given user on the target site.
1Balbooa
1Gridbox
Aug 5, 2026
Jul 29, 2026
10.0 CRITICAL· v4
9.8 CRITICAL· v3
N/A· v2
Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2 - The resetPassword method allows actors to reset any user password, allowing to login and act as these users - excluding supe...Show more
Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2 - The resetPassword method allows actors to reset any user password, allowing to login and act as these users - excluding super admins.Show less
1Balbooa
1Gridbox
Aug 5, 2026
Jul 29, 2026
9.2 CRITICAL· v4
7.5 HIGH· v3
N/A· v2
Joomla Extension - balbooa.com - Unauthenticated arbitrary file read in Gridbox < 2.20.2 - The photo viewer allows unauthenticated attackers to view arbitrary files.
1Balbooa
1Gridbox
Aug 5, 2026
Jul 29, 2026
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Joomla Extension - balbooa.com - Stored cross-site scripting via a comment avatar in Gridbox < 2.20.2
1Balbooa
1Gridbox
Aug 5, 2026
Jul 29, 2026
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Joomla Extension - balbooa.com - Various unauthenticated file system disclosure in Gridbox < 2.20.2
1Balbooa
1Gridbox
Aug 5, 2026
Jul 29, 2026
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Joomla Extension - balbooa.com - Payment bypass in Gridbox < 2.20.2
1Balbooa
1Gridbox
Aug 5, 2026
Jul 29, 2026
9.2 CRITICAL· v4
9.8 CRITICAL· v3
N/A· v2
Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 - Multiple SQLi vectors allow unauthenticated actors to inject SQL in queries.
1Balbooa
1Gridbox
Aug 5, 2026
Jul 29, 2026
9.2 CRITICAL· v4
7.5 HIGH· v3
N/A· v2
Joomla Extension - balbooa.com - Unauthenticated recursive directory deletion < 2.20.2 - The generateNewApp method allows actors to recursively delete directories.
1Balbooa
1Gridbox
Aug 5, 2026
Jul 29, 2026
9.4 CRITICAL· v4
8.8 HIGH· v3
N/A· v2
Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 - File upload methods allows authenticated attackers to upload arbitrary files. Turns into an authenticated RCE if combined with CV...Show more
Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 - File upload methods allows authenticated attackers to upload arbitrary files. Turns into an authenticated RCE if combined with CVE-2026-65884 as the required account can be created by the attacker.Show less
1Balbooa
1Gridbox
Aug 5, 2026
Jul 29, 2026
10.0 CRITICAL· v4
9.8 CRITICAL· v3
N/A· v2
Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The registration method allows users provided usergroup IDs, allowing unauthenticated actors to register new accounts with administrative permis...Show more
Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The registration method allows users provided usergroup IDs, allowing unauthenticated actors to register new accounts with administrative permissions.Show less
1Balbooa
1Gridbox
Nov 21, 2024
Jun 14, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Balbooa Gridbox extension version 2.4.0 and previous versions for Joomla! is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerabilit...Show more
The Balbooa Gridbox extension version 2.4.0 and previous versions for Joomla! is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability via a crafted URL to execute script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.Show less