Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.balbooa.com/ |
|
Tue, 29 Sep 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Joomla Extension - balbooa.com - Unauthenticated RCE via field shortcode injection in Balbooa Forms < 2.4.3.4 - Balbooa Forms supports administrator-defined PHP code which runs after a public form submission. The feature also supports form-field shortcodes inside that PHP. Before calling `eval()`, the component replaces each shortcode with the raw value submitted by the visitor, leading to an RCE vector. A public form must use the product's optional PHP-after-submission action and interpolate an attacker-controlled field shortcode inside a double-quoted PHP string to be vulnerable. | |
| Title | Joomla Extension - balbooa.com - Unauthenticated RCE via field shortcode injection in Balbooa Forms < 2.4.3.4 | |
| Weaknesses | CWE-94 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Joomla
Published:
Updated: 2026-09-29T17:04:35.280Z
Reserved: 2026-09-29T04:38:08.434Z
Link: CVE-2026-102425
No data.
Status : Received
Published: 2026-09-29T17:17:06.210
Modified: 2026-09-29T17:17:06.210
Link: CVE-2026-102425
No data.
OpenCVE Enrichment
No data.
-
CWE-94
Improper Control of Generation of Code ('Code Injection')