← Back to CVE List
Vulnerability Intelligence Report
Extension - balbooa.com - SQL injection in Balbooa Forms component version 1.0.0 - 2.3.1.1 for Joomla

CVE-2025-49485

A SQL injection vulnerability in the Balbooa Forms plugin 1.0.0-2.3.1.1 for Joomla allows privileged users to execute arbitrary SQL commands via the 'id' parameter.

No Active Exploit Signals
CVSS Base Score
8.6
HIGH
EPSS Probability:0.26%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-89 ↗CWE-89: Improper Neutralization of Special Elements used in an SQL Command

Affected Products & Versions

Vendor Product Affected Versions
balbooa.com Balbooa Forms component for Joomla 1.0.0-2.3.1.1 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.261%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityJoomla! Project · Vendor · USA
Reserved2025-06-05T13:21:31
Published2025-07-18T09:51:01
Last Updated2025-07-20T08:52:54

LINK COPIED TO CLIPBOARD