Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.balbooa.com/ |
|
Wed, 30 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 30 Sep 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Balbooa.com
Balbooa.com balbooa.com Balbooa Forms Extension For Joomla |
|
| Vendors & Products |
Balbooa.com
Balbooa.com balbooa.com Balbooa Forms Extension For Joomla |
Tue, 29 Sep 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Joomla Extension - balbooa.com - Unauthenticated RCE via field shortcode injection in Balbooa Forms < 2.4.3.4 - Balbooa Forms supports administrator-defined PHP code which runs after a public form submission. The feature also supports form-field shortcodes inside that PHP. Before calling `eval()`, the component replaces each shortcode with the raw value submitted by the visitor, leading to an RCE vector. A public form must use the product's optional PHP-after-submission action and interpolate an attacker-controlled field shortcode inside a double-quoted PHP string to be vulnerable. | |
| Title | Joomla Extension - balbooa.com - Unauthenticated RCE via field shortcode injection in Balbooa Forms < 2.4.3.4 | |
| Weaknesses | CWE-94 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Joomla
Published:
Updated: 2026-09-30T20:11:07.881Z
Reserved: 2026-09-29T04:38:08.434Z
Link: CVE-2026-102425
Updated: 2026-09-30T19:51:23.494Z
Status : Awaiting Analysis
Published: 2026-09-29T17:17:06.210
Modified: 2026-09-30T21:17:04.127
Link: CVE-2026-102425
No data.
OpenCVE Enrichment
Updated: 2026-09-30T20:30:18Z
-
CWE-94
Improper Control of Generation of Code ('Code Injection')