Threat intel / CVE tracker

CVE-2026-56291

Critical KEV · actively exploited PoC available
CVSS base score
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

Vendor
balbooa
Product
forms
Affected
balbooa forms
Weakness
CWE-434 · File upload
Published
Jul 9, 2026
Last modified
Jul 24, 2026
CVSS version
v3.1
Views
13
// References & exploits
NVD record Search PoCs