CVE-2026-102424

CVE-2026-102424 published: Joomla Extension - balbooa.com - Unauthenticated path traversal exfiltrates local files through auto-reply attachments in Balbooa Forms < 2.4.3.4 - Balbooa Forms accepts upload-field state as Guest-controlled JSON during public form submission. For every ob...

View full NVD advisory → ← Back to CVE watch