Skip to content
COOEY

FAIL › dossier

Balbooa

VENDOR

· dossier confidence 50%

Balbooa is a vendor with a critical security posture, evidenced by two confirmed RCE vulnerabilities in July 2026 involving unauthenticated file uploads in their Forms extension.

PROFILE
CategoryvendorWhat they doBalbooa is a vendor providing software components, specifically a Forms extension, for enterprise applications.
SECURITY POSTURE

Critical security posture with two confirmed RCE vulnerabilities in July 2026 involving unauthenticated file uploads.

Notable failures
  • CVE-2026-56291: Unauthenticated arbitrary file upload leading to full RCE
  • CVE-2026-56291: Balbooa Forms extension enables unauthenticated RCE via arbitrary file upload
  • High severity RCE in Balbooa Forms
Patterns: Repeated unpatched edge-device RCEs
FAILURE HISTORY · 6
DATEEVENTSEVSUMMARY
2026-07-10 CVE-2026-56291 high Balbooa Forms allows unauthenticated arbitrary file upload leading to full RCE.
2026-07-09 CVE-2026-56291 critical Balbooa Forms extension enables unauthenticated RCE via arbitrary file upload.
2026-07-29 CVE-2026-65890 critical CVE-2026-65890: Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20
2026-07-29 CVE-2026-65887 critical CVE-2026-65887: Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gri
2026-07-29 CVE-2026-65888 critical CVE-2026-65888: Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.2
2026-07-29 CVE-2026-65884 critical CVE-2026-65884: Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The
Open questions: Balbooa's corporate identity and ownership structure · Balbooa's founding date and headquarters location · Balbooa's employee count and market size
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-14 04:03:05.940671+00:00