CVE WATCH / VULNERABILITY DETAIL

CVE-2026-102784

UNKNOWNCVSS 0NVD feed

Published 8 October 2026 · tracked since 9 October 2026

Description

Joomla Extension - balbooa.com - CSRF in language installation feature Gridbox < 2.20.4.0 - PagesController uses a trait that validates the Joomla session token only when the HTTP method is POST. addLanguage does not require POST inside the action and reads url and zip through the generic request in

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-102784 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-102784

UNKNOWNCVSS 0NVD feed

Published 8 October 2026 · tracked since 9 October 2026

Description

Joomla Extension - balbooa.com - CSRF in language installation feature Gridbox < 2.20.4.0 - PagesController uses a trait that validates the Joomla session token only when the HTTP method is POST. addLanguage does not require POST inside the action and reads url and zip through the generic request in

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]