Threat intel / CVE tracker
CVE-2026-56291
Critical KEV · actively exploited PoC availableCVSS base score
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HJoomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
Vendor
balbooa
Product
forms
Affected
balbooa forms
Weakness
CWE-434 · File upload
Published
Jul 9, 2026
Last modified
Jul 24, 2026
CVSS version
v3.1
Views
13
// References & exploits