CVE-2026-101127

LOWCVSS 8.6 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Joomla Extension - balbooa.com - Unauthenticated upload filename stored XSS in Balbooa Forms < 2.4.3.4 - The public form upload endpoint validates the uploaded file's extension and detected MIME type, but stores the attacker-supplied original multipart filename verbatim in `#__baforms_submissions_attachments.name`. A later anonymous form submission associates that temporary attachment with the newly created submission. When an administrator opens the submission, the component's JavaScript retrieves the stored attachment record and concatenates `file.name` directly into an HTML string. The complete string is assigned to `innerHTML`.

0.0/ 10 priority

Sources & remediation

Other references
Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-01: 110-01
Referenced assets1 URL
By indicator
Full discourse1 post
  • Ryx@PadhiyarRushi

    Uploaded filename in Balbooa Forms is stored XSS, rendered in the admin view! CVE-2026-101127 (CVSS 8.6): Anonymous submit, malicious filename, admin opens the submission. Same 2.4.3.4 drop! Two siblings on the attachment path: - CVE-2026-101112 deletes any visitor’s temp attachment. - CVE-2026-101126 rewrites attachment names and references on submit. All five are unauth through a public form. https://mysites.guru/vulnerabilities/CVE-2026-102425/ #Cybersecurity #AI #AISecurity #MCP #Claude #GPT #Infosec #Trending #Joomla #XSS #BugBounty

    00031116
    943 followersView on X

Explore more