CVE-2026-102425

CVE-2026-102425 published: Joomla Extension - balbooa.com - Unauthenticated RCE via field shortcode injection in Balbooa Forms < 2.4.3.4 - Balbooa Forms supports administrator-defined PHP code which runs after a public form submission. The feature also supports form-field shortcodes ...

View full NVD advisory → ← Back to CVE watch