Vulnerability Details CVE-2026-65885
Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 - File upload methods allows authenticated attackers to upload arbitrary files. Turns into an authenticated RCE if combined with CVE-2026-65884 as the required account can be created by the attacker.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 20.8%
CVSS Severity
CVSS v3 Score 8.8
Products affected by CVE-2026-65885
-
cpe:2.3:a:balbooa:gridbox:2.20.1