← Vulnerability feed

Vulnerability record · CVE-2018-11690 · published 14 June 2018

CVE-2018-11690: Balbooa gridbox cross-site scripting vulnerability

Balbooa · Gridbox

The Balbooa Gridbox extension version 2.4.0 and previous versions for Joomla! is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability via a crafted URL to execute script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.

6.1 CVSS 3.0 Medium EPSS 34% · top 1.7% CWE-79 · Cross-site scripting
6.1CVSS 3.0 base score, v2 4.3
34%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References, 8 tagged exploit
17 Jun 2026Last modified by NVD

Description

The Balbooa Gridbox extension version 2.4.0 and previous versions for Joomla! is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability via a crafted URL to execute script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-11690 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2026-65887Balbooa gridbox improper access control vulnerabilityJoomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2 - The resetPassword method allows actors to reset any u…EPSS 0.52%10.0CVE-2026-65888Balbooa gridbox improper access control vulnerabilityJoomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2 - The socialLogin method allows actors to login as any given user…EPSS 0.52%10.0CVE-2026-65884Balbooa gridbox improper access control vulnerabilityJoomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The registration method allows users provided usergroup IDs, allowing una…EPSS 0.52%9.4CVE-2026-65885Balbooa gridbox unrestricted file upload vulnerabilityJoomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 - File upload methods allows authenticated attackers to uplo…EPSS 0.52%9.2CVE-2026-65886Balbooa gridbox path traversal vulnerabilityJoomla Extension - balbooa.com - Unauthenticated arbitrary file read in Gridbox < 2.20.2 - The photo viewer allows unauthenticated attackers to view …EPSS 0.55%9.2CVE-2026-65889Balbooa gridbox path traversal vulnerabilityJoomla Extension - balbooa.com - Unauthenticated recursive directory deletion < 2.20.2 - The generateNewApp method allows actors to recursively delet…EPSS 0.44%9.2CVE-2026-65890Balbooa gridbox sql injection vulnerabilityJoomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 - Multiple SQLi vectors allow unauthenticated actors to inject SQL…EPSS 0.50%7.3CVE-2026-65947Balbooa gridbox cross-site request forgery vulnerabilityJoomla Extension - balbooa.com - Various CSRF vectors in the admin interface in Gridbox < 2.20.2EPSS 0.19%

Source: NIST National Vulnerability Database (record CVE-2018-11690), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.