CVE-2026-65885
balbooa.com Gridbox extension for Joomla
Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 - File upload methods allows authenticated attackers to upload arbitrary files. Turns into an authenticated RCE if combined with CVE-2026-65884 as the required account can be created by the attacker.
- CVSS
- 9.4
- EPSS
- - - percentile
- CISA KEV
- Not listed
- Published
- 2026.07.29