Balbooa Joomla Forms Builder 2.0.6 contains an unauthenticated SQL injection vulnerability in the form submission handler that allows remote attackers to execute arbitrary SQL queries. Attackers can send POST requests to the com_baforms component with malicious JSON payloads in the 'id' field parameter to extract sensitive database information.
References
Configurations
No configuration.
History
24 Jul 2026, 19:10
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
10 May 2026, 13:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-10 13:16
Updated : 2026-07-25 10:10
NVD link : CVE-2021-47930
Mitre link : CVE-2021-47930
CVE.ORG link : CVE-2021-47930
JSON object : View
Products Affected
No product.
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
