← Back to browse · API

CVE-2026-65888

Severity
CRITICAL
CVSS
10.0
EPSS
0.00284
Risk score
40.1
CISA KEV
No
PoC
No
Published
2026-07-29
Modified
2026-08-12
First seen
2026-08-05
Aliases
EUVD-2026-50356, GHSA-84GF-CFMW-8QQQ
Products
balbooa.com:Gridbox extension for Joomla 1.0.0-2.20.1, balbooa:gridbox
Sources
euvd EUVD-2026-50356
nvd CVE-2026-65888

Description

Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2 - The socialLogin method allows actors to login as any given user on the target site.

References