PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jul 18, 2026

Balbooa Forms < 2.4.1 - Unauthenticated Arbitrary File Upload

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsdomain, subdomain, ipv4
CostFree
2.6k
Times Used
continuous scan runs
0
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2026-56291
10.0
CVSScritical
Exploitable remotely over the internet · no authentication required.

Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
balbooa.com Balbooa Forms extension for Joomlaby balbooa.com
1.0-2.4.0
Updated Sep 9, 2026View on NVD →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

Balbooa Forms < 2.4.1 - Unauthenticated Arbitrary File Upload CVE-2026-56291 Scanner | S4E