Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3130 articles · 181769 vulns · 37/41 feeds (7d)
← Back to list
—
CVE-2026-65885KEVEXPLOITED
balbooa.com · Gridbox extension for Joomla

Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2

Description

Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 - File upload methods allows authenticated attackers to upload arbitrary files. Turns into an authenticated RCE if combined with CVE-2026-65884 as the required account can be created by the attacker.

Affected Products

VendorProductVersions
balbooa.comGridbox extension for Joomla1.0.0-2.20.1

References

  • https://www.balbooa.com/gridbox(product)
  • https://mysites.guru/blog/gridbox-23-critical-vulnerabilities/(third-party-advisory)

Related News (1 articles)

Tier C
VulDB7h ago
CVE-2026-65885 | balbooa Gridbox Extension up to 2.20.1 unrestricted upload
→ No new info (linked only)
CISA KEV✅ Yes
Actively exploited✅ Yes
CWECWE-434
PublishedJul 29, 2026
Last enriched6h ago
Trending Score92
Source articles1
Independent1
Info Completeness7/14
Missing: cvss, epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-65884EXPKEV
Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2
Trending: 101
NONECVE-2026-65880
Joomla Extension - joomshaper.com - Unauthenticated remote code execution in Balbooa Forms < 2.4.3
Trending: 31
NONECVE-2026-65886
Joomla Extension - balbooa.com - Unauthenticated arbitrary file read in Gridbox < 2.20.2
Trending: 30
NONECVE-2026-65889
Joomla Extension - balbooa.com - Unauthenticated recursive directory deletion in Gridbox < 2.20.2
Trending: 30
NONECVE-2026-65890
Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2
Trending: 30

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 29, 2026
Added to CISA KEV
Jul 29, 2026
Discovered by ZDM
Jul 29, 2026
Actively Exploited
Jul 29, 2026