CVE-2026-101127

CVE-2026-101127 published: Joomla Extension - balbooa.com - Unauthenticated upload filename stored XSS in Balbooa Forms < 2.4.3.4 - The public form upload endpoint validates the uploaded file's extension and detected MIME type, but stores the attacker-supplied original multipart file...

View full NVD advisory → ← Back to CVE watch