SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-65885

HIGH · CVSS 8.8 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-07-29 · Last synced 2026-08-28

CyberRota Analysis

AI-Generated

The Gridbox extension for Joomla versions prior to 2.20.2 is vulnerable to an authenticated arbitrary file upload, allowing attackers with valid credentials to upload malicious files. This vulnerability can lead to remote code execution when exploited in conjunction with another identified vulnerability, enabling attackers to gain further control over the affected system. Joomla administrators and users of the Gridbox extension should prioritize patching to mitigate potential exploitation.

CVE
CVE-2026-65885
Severity
HIGH
CVSS
8.8
EPSS
0.29%

Original NVD Description

Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 - File upload methods allows authenticated attackers to upload arbitrary files. Turns into an authenticated RCE if combined with CVE-2026-65884 as the required account can be created by the attacker.

Related CVEs

Other vulnerabilities affecting the same vendor(s)