
Uploaded filename in Balbooa Forms is stored XSS, rendered in the admin view! CVE-2026-101127 (CVSS 8.6): Anonymous submit, malicious filename, admin opens the submission. Same 2.4.3.4 drop! Two siblings on the attachment path: - CVE-2026-101112 deletes any visitor’s temp attachment. - CVE-2026-101126 rewrites attachment names and references on submit. All five are unauth through a public form. https://mysites.guru/vulnerabilities/CVE-2026-102425/ #Cybersecurity #AI #AISecurity #MCP #Claude #GPT #Infosec #Trending #Joomla #XSS #BugBounty
