All CVEs
Vulnerability intelligence

CVE-2026-56291

CWE-434

Joomla Extension balbooa.com Unauthenticated file upload in Balbooa Forms extension < 2.4.1 The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

CVSS Score
10
Critical
EPSS — Exploit Probability
76%
Riskier than 100% of all CVEs
Exploitation
Confirmed in the wild
KEV since 2026-07-10
Remediation
unknown
Federal deadline 2026-07-13
NVD entry PoC / advisory CISA KEV

6 articles across 5 outlets · first covered Jul 10, 2026 · latest Jul 13, 2026

Tracked incidents

Associated threat actors

Coverage timeline