Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.4

CVE-2026-61425: Joomla Gridbox Extension - Unauthenticated Admin Access

CVE-2026-61425 CVE-2026-61425
Summary

The Gridbox extension in Joomla versions before 1.6.0 has a security flaw that could allow an attacker to access the admin area without logging in. This means that sensitive data and settings could be compromised. Update to version 1.6.0 or later to fix this issue.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
balbooa.com gridbox extension for joomla 1.0.0-2.20.0.2
Original title
Joomla Extension - balbooa.com - Authentication bypass in Gridbox < 1.6.0
Original description
The Joomla extension Gridbox is vulnerable an authenticated bypass, potentially leading to full admin access.
nvd CVSS4.0 9.4
Vulnerability type
CWE-288 Authentication Bypass Using Alternate Path
Published: 20 Jul 2026 · Updated: 20 Jul 2026 · First seen: 20 Jul 2026