Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3123 articles · 181730 vulns · 37/41 feeds (7d)
← Back to list
—
CVE-2026-65890
balbooa.com · gridbox extension for joomla

Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2

Description

Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 - Multiple SQLi vectors allow unauthenticated actors to inject SQL in queries.

Affected Products

VendorProductVersions
balbooa.comgridbox extension for joomla1.0.0-2.20.1

References

  • https://www.balbooa.com/gridbox(product)
  • https://mysites.guru/blog/gridbox-23-critical-vulnerabilities/(third-party-advisory)

Related News (1 articles)

Tier C
VulDB4h ago
CVE-2026-65890 | Balbooa Gridbox Extension up to 2.20.1 sql injection
→ No new info (linked only)
CISA KEV❌ No
Actively exploited❌ No
CWECWE-89
PublishedJul 29, 2026
Trending Score30
Source articles1
Independent1
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-65884EXPKEV
Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2
Trending: 102
NONECVE-2026-65885EXPKEV
Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2
Trending: 92
NONECVE-2026-65880
Joomla Extension - joomshaper.com - Unauthenticated remote code execution in Balbooa Forms < 2.4.3
Trending: 31
NONECVE-2026-65886
Joomla Extension - balbooa.com - Unauthenticated arbitrary file read in Gridbox < 2.20.2
Trending: 30
NONECVE-2026-65889
Joomla Extension - balbooa.com - Unauthenticated recursive directory deletion in Gridbox < 2.20.2
Trending: 30

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 29, 2026
Discovered by ZDM
Jul 29, 2026