Balbooa Joomla Forms Builder 2.0.6 contains an unauthenticated SQL injection vulnerability in the form submission handler that allows remote attackers to execute arbitrary SQL queries. Attackers can send POST requests to the com_baforms component with malicious JSON payloads in the 'id' field parameter to extract sensitive database information.
Metrics
Affected Vendors & Products
References
History
Tue, 12 May 2026 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 10 May 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Balbooa
Balbooa balbooa Joomla Forms Builder |
|
| Vendors & Products |
Balbooa
Balbooa balbooa Joomla Forms Builder |
Sun, 10 May 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Balbooa Joomla Forms Builder 2.0.6 contains an unauthenticated SQL injection vulnerability in the form submission handler that allows remote attackers to execute arbitrary SQL queries. Attackers can send POST requests to the com_baforms component with malicious JSON payloads in the 'id' field parameter to extract sensitive database information. | |
| Title | Balbooa Joomla Forms Builder 2.0.6 SQL Injection Unauthenticated | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-12T02:38:21.372Z
Reserved: 2026-02-01T11:24:18.716Z
Link: CVE-2021-47930
Updated: 2026-05-12T02:38:17.059Z
Status : Received
Published: 2026-05-10T13:16:29.163
Modified: 2026-05-10T13:16:29.163
Link: CVE-2021-47930
No data.