Balbooa Gridbox – several critical flaws, updating alone is not enough
เวอร์ชันที่ปลอดภัย: Balbooa Gridbox 2.20.2 or newer · via Balbooa (account required)
สรุปข้อมูลสำคัญ
com_gridbox)ช่องโหว่นี้คืออะไร
Balbooa Gridbox is a page builder for Joomla from the same vendor as Balbooa Forms. Versions up to and including 2.20.1 became known for several severe security flaws – seven of them carry their own CVE identifier.
Three reach the maximum score of 10 out of 10: a privilege escalation that allowed an administrator account to be created without a login (CVE-2026-65884), resetting anyone else’s password (CVE-2026-65887) and taking over existing accounts (CVE-2026-65888). On top of that come file access without a login, an SQL injection and a bypassable permission check.
This is the decisive point: with these flaws an update is not necessarily enough. If your site ran on a version up to 2.20.1 for any length of time, a planted administrator account may already exist. The update closes the way in – an account that is already there stays until it is removed.
เว็บไซต์ของคุณได้รับผลกระทบหรือไม่ – วิธีตรวจสอบ
- Open the back end
Sign in to the Joomla administrator.
- Check the version
Open Extensions›Manage›Manage and filter for "Gridbox". If the version is 2.20.1 or lower, the site is vulnerable.
- Review the user list
Open Users›Manage and look for accounts you did not create yourself – especially ones with an odd user name and a throwaway address. Do not delete blindly; check first.
- Go through the extensions
In Extensions›Manage also review the plugin list for entries you never installed.
วิธีปิดช่องโหว่นี้
- Before updating: back up
Back up files and database before you update.
- Open the update centre
Go to System›Update›Extensions and click Check for updates.
- Update Gridbox
Select the entry and update to 2.20.2 or newer. 2.20.1 is not enough.
- Afterwards: check accounts
Only after the update, go through the user list – an account created earlier does not disappear on its own.
แหล่งดาวน์โหลดอย่างเป็นทางการ: via Balbooa (account required). ตรวจสอบให้แน่ใจว่าเป็นเวอร์ชันอย่างน้อย Balbooa Gridbox 2.20.2 or newer.
เว็บไซต์ถูกแฮกไปแล้วหรือไม่
ต้องการความช่วยเหลือในการกู้คืนเว็บไซต์ใช่หรือไม่ ค้นหาผู้เชี่ยวชาญที่เหมาะสมได้ที่ไดเรกทอรีผู้ให้บริการ Joomla
แหล่งข้อมูล & อ่านเพิ่มเติม
- CVE-2026-65884 – privilege escalationSeverity 10 out of 10
- CVE-2026-65887 – resetting other passwordsSeverity 10 out of 10
- CVE-2026-65888 – account takeoverSeverity 10 out of 10
- Balbooa (vendor)Source of the safe version 2.20.2
ให้ยึดข้อมูลอย่างเป็นทางการจากผู้พัฒนาแต่ละรายเป็นหลักเสมอ หน้านี้รวบรวมข้อมูลที่เปิดเผยต่อสาธารณะไว้อย่างเป็นกลาง
Supporters of this site
htprotect.org is a free, vendor-independent information service. It is supported by:

Joomla host from Germany with active community support – discovered the first attack on the JCE vulnerability.
fc-hosting.deSpecialised in cleaning, maintaining and securing Joomla and WordPress websites.
website-bereinigung.deSupport this project
You run a hosting or Joomla service and would like to support htprotect.org – and be listed here as a supporter? Every contribution helps to warn and protect those affected faster.
Prefer to give privately, without a listing? A little something for the tip jar is just as welcome.
Manufactures and installs construction-site signs, hoardings and façade solutions – including design and 3D visualisation.
bauschildundservice.deProfessional IT support from Czechia – Windows management, domain administration and web hosting.
defendersoft.czTravel portal from Germany – package holidays, hotels and flights online, with personal travel-agency advice.
onlineweg.deCreative agency from Brandenburg – web design, print media, photography and 360° panoramas from a single source.
criadero.deIT service provider from Wächtersbach – Joomla websites, PC service, hardware and software.
jahnedv.deInformation-security consulting from Berlin – security analyses, risk management and ISO 27001 for SMEs.
isari-consult.de