📦

gridbox

Vendor: balbooa

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 1 Remote Access
Total CVEs 12 Total Indexed
Avg. EPSS 3.03% Exploit Prob.
Latest CVE CVE-2026-65947 Jul 29

Security Vulnerability Index

Page 1 / 2
7.3 CVSS

Joomla Extension - balbooa.com - Various CSRF vectors in the admin interface in Gridbox < 2.20.2

EPSS: 0.13%
10.0 CVSS

Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2 - The socialLogin method allows actors to login as any given user on the target site.

EPSS: 0.29%
10.0 CVSS

Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2 - The resetPassword method allows actors to reset any user password, allowing to login and act as these users - excluding super admins.

EPSS: 0.30%
9.2 CVSS

Joomla Extension - balbooa.com - Unauthenticated arbitrary file read in Gridbox < 2.20.2 - The photo viewer allows unauthenticated attackers to view arbitrary files.

EPSS: 0.36%
6.1 CVSS

Joomla Extension - balbooa.com - Stored cross-site scripting via a comment avatar in Gridbox < 2.20.2

EPSS: 0.16%
5.3 CVSS

Joomla Extension - balbooa.com - Various unauthenticated file system disclosure in Gridbox < 2.20.2

EPSS: 0.21%
5.3 CVSS

Joomla Extension - balbooa.com - Payment bypass in Gridbox < 2.20.2

EPSS: 0.20%
9.2 CVSS

Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 - Multiple SQLi vectors allow unauthenticated actors to inject SQL in queries.

EPSS: 0.28%
9.2 CVSS

Joomla Extension - balbooa.com - Unauthenticated recursive directory deletion < 2.20.2 - The generateNewApp method allows actors to recursively delete directories.

EPSS: 0.29%