Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Pascal Lohmann

#10313of 56,326
28.6Total CVSS
Vulnerabilities · 3
Critical
3
PT-2026-65785
10
2026-07-29
Balbooa.Com · Gridbox Extension For Joomla · CVE-2026-65884
**Name of the Vulnerable Software and Affected Versions** Gridbox versions prior to 2.20.2 **Description** A privilege escalation issue exists in the registration method of the Gridbox extension for Joomla. This flaw allows unauthenticated actors to register new accounts with administrative permissions by providing specific usergroup IDs. **Recommendations** Update Gridbox to version 2.20.2 or later.
PT-2026-65786
9.4
2026-07-29
Balbooa.Com · Gridbox Extension For Joomla · CVE-2026-65885
Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 - File upload methods allows authenticated attackers to upload arbitrary files. Turns into an authenticated RCE if combined with CVE-2026-65884 as the required account can be created by the attacker.
PT-2026-65799
9.2
2026-07-29
Balbooa.Com · Gridbox Extension For Joomla · CVE-2026-65886
Joomla Extension - balbooa.com - Unauthenticated arbitrary file read in Gridbox < 2.20.2 - The photo viewer allows unauthenticated attackers to view arbitrary files.