HTProtect.org
HTProtect HTProtect JOOMLA SECURITY
htprotect.org Vulnerabilities & update guides
New htprotect.app - Centralized Joomla Site Management for Multiple Websites
Security vulnerability

Balbooa Forms – critical upload flaw with code execution

Critical Actively exploitedCVE-2026-67364
Act now
Update Balbooa Forms to 2.4.3.2 or newer immediately – and clean up as well if you suspect a compromise.

Secure version: Balbooa Forms 2.4.3.2 or newer · via Balbooa

At a glance

Affected extension
Balbooa Forms – form extension (com_baforms)
Vendor
Type of flaw
Two flaws without a login: file upload through the form front end and PHP code injected through an unchecked address parameter – both leading to remote code execution (RCE)
Affected versions
All versions up to and including 2.4.3.1
Secure version
Balbooa Forms 2.4.3.2 or newer   Download
Severity
Critical · actively exploited
Joomla compatibility
Joomla 4 / 5 / 6
Status / published
Published/patched: 9 July 2026

What is this about?

Balbooa Forms (com_baforms) builds contact and sign-up forms for Joomla. Forms can accept file attachments – and exactly that upload path was left open: the front-end call that stores an attachment could be triggered without logging in and checked neither a security token (CSRF) nor the file type.

As a result, an attacker can upload an executable PHP file. It is placed in a publicly reachable sub-folder of the upload directory and can then be opened straight from the browser – the injected code runs on the server (remote code execution). At that point the whole site can be taken over.

Two flaws are now known. The first affected the file upload and was fixed on 9 July 2026 in 2.4.1 (CVE-2026-56291). A second one followed on 19 August 2026: through a building block that takes a value from the address bar unchecked, an attacker could inject and run their own PHP code without logging in (CVE-2026-67364, severity 10 out of 10). Every version up to and including 2.4.3.1 is affected; only 2.4.3.2 is safe. Worth knowing: the second flaw only bites if a form uses a custom PHP handler with exactly that building block and has no reCAPTCHA in front of it - so it does not hit every installation. That does not make the update less urgent: if you cannot say for certain that it does not apply to you, assume it does. The flaw is tracked as CVE-2026-56291 and, according to the report, is already being exploited in the wild; no public exploit code was released.

Am I affected? – How to check

  1. Open the back end

    Log in to the Joomla administrator.

  2. Check the version

    Under ExtensionsManageManage, filter for Balbooa Forms and read off the version.

  3. Assess the version

    If the version is 2.4.3.1 or older, action is urgently needed.

  4. Watch for traces

    Check the folder images/baforms/uploads/ for foreign .php files and your Users list for unknown administrator accounts.

How to fix it

Before any update: back up
Back up your files and database before updating – so you can roll back if anything goes wrong (e.g. via Akeeba Backup or your host).
  1. Open the Update center

    Go to SystemUpdateExtensions and click Check for updates.

  2. Update Balbooa Forms

    Select the entry and update to 2.4.3.2 or newer.

  3. Verify the version

    Then confirm that the new version has been applied.

Manual installation (alternative)
If no update appears, download the package from your Balbooa account and install it via ExtensionsManageInstall.

Official source: via Balbooa. Make sure you have at least Balbooa Forms 2.4.3.2 or newer.

Has the site already been attacked?

If compromised, an update is not enough
The update closes the hole but does not remove any malware already uploaded. Check images/baforms/uploads/ and the surrounding folders for foreign .php files, review your Users list for new Super Users, and if you find anything change all passwords (Joomla admin, FTP/SSH, database). When in doubt, have the site professionally cleaned.

Need help with the clean-up? Find qualified specialists in the Joomla Service Providers Directory.

Sources & further reading

The official information from the respective vendor always takes precedence. This page neutrally summarises publicly available information.

Related vulnerabilities

Other extensions with comparable weaknesses. Check whether any of them is installed on your site.

Balbooa GridboxCriticalactively exploited
Helix3 FrameworkCriticalactively exploited
JoomShaperLearn more
Astroid FrameworkCriticalactively exploited
TemPlazaLearn more
Supporters

Supporters of this site

htprotect.org is a free, vendor-independent information service. It is supported by:

Host & community
FC-Hosting

Joomla host from Germany with active community support – discovered the first attack on the JCE vulnerability.

fc-hosting.de
Initiator & operator
Website-Bereinigung.de

Specialised in cleaning, maintaining and securing Joomla and WordPress websites.

website-bereinigung.de

Support this project

You run a hosting or Joomla service and would like to support htprotect.org – and be listed here as a supporter? Every contribution helps to warn and protect those affected faster.

Prefer to give privately, without a listing? A little something for the tip jar is just as welcome.

Support HTProtect now
Bauschild & Service

Manufactures and installs construction-site signs, hoardings and façade solutions – including design and 3D visualisation.

bauschildundservice.de
IT Specialista

Professional IT support from Czechia – Windows management, domain administration and web hosting.

defendersoft.cz
onlineweg.de

Travel portal from Germany – package holidays, hotels and flights online, with personal travel-agency advice.

onlineweg.de
Criadero

Creative agency from Brandenburg – web design, print media, photography and 360° panoramas from a single source.

criadero.de
Jahn EDV-Dienst GmbH

IT service provider from Wächtersbach – Joomla websites, PC service, hardware and software.

jahnedv.de
IsariConsult

Information-security consulting from Berlin – security analyses, risk management and ISO 27001 for SMEs.

isari-consult.de