CVE-2026-65885
EUVD-2026-5029829.07.2026, 13:19
Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 - File upload methods allows authenticated attackers to upload arbitrary files. Turns into an authenticated RCE if combined with CVE-2026-65884 as the required account can be created by the attacker.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| balbooa | gridbox | 𝑥 < 2.20.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration