Critical RCE in Balbooa Forms via Shortcode Injection
CVE-2026-102425 is a critical unauthenticated remote code execution vulnerability in the Joomla Balbooa Forms extension allowing code injection via unsanitized field shortcodes.
CVE search metadata
CVE search record: CVE-2026-102425. KEV: no. Product: Balbooa Forms (< 2.4.3.4). Brief: Critical RCE in Balbooa Forms via Shortcode Injection. Brief link: https://feed.craftedsignal.io/briefs/2026-09-cve-2026-102425/
CVE-2026-102425 is a critical vulnerability (CVSS 9.5) affecting the Balbooa Forms extension (com_baforms) for Joomla, versions 1.0.0 through 2.4.3.3. The flaw is rooted in how the component processes PHP code configured to run after a form submission. Administrators can define PHP snippets that include form-field shortcodes; however, the component fails to sanitize these values before passing them to an eval() function. An unauthenticated remote attacker can supply malicious input via a public form submission, breaking out of a double-quoted string to execute arbitrary PHP code on the server.
This vulnerability requires specific configuration: the site must have a public form that utilizes the "PHP-after-submission" feature containing field or URL shortcodes. Because a functional exploit proof-of-concept is publicly available, organizations using affected versions of Balbooa Forms are at immediate risk of compromise.
Attack Chain
- Attacker discovers a Joomla site running an vulnerable version of com_baforms (v1.0.0 - 2.4.3.3).
- Attacker probes the target by sending a GET request to index.php with the task=form.loadAjaxForm parameter to identify form IDs.
- Attacker identifies a public form that utilizes the "PHP-after-submission" action.
- Attacker constructs a malicious payload designed to break out of the PHP double-quoted string (e.g., "; system('id'); //).
- Attacker sends a POST request to the form action with task=form.message containing the malicious payload in a form field.
- The server-side component replaces the form shortcode with the attacker's payload and executes the resulting string via eval().
- The injected PHP code executes on the web server, allowing for unauthorized command execution or the dropping of webshells such as up.php.
Impact
Successful exploitation results in full remote code execution, granting attackers the ability to manipulate the underlying server, exfiltrate data, or establish persistence. Vulnerable sites may be subject to automated mass-exploitation, as evidenced by the availability of scripting tools that support automated scanning and remote shell deployment in common Joomla directories like images/baforms/uploads/.
Recommendation
- Immediately upgrade Balbooa Forms to version 2.4.3.4 or higher to patch CVE-2026-102425.
- Audit all forms for "PHP-after-submission" actions and temporarily disable those utilizing field or URL shortcodes until the patch is applied.
- Implement reCAPTCHA on all public-facing forms to mitigate automated exploitation attempts.
- Inspect the directory images/baforms/uploads/ and other common upload paths for unauthorized PHP files or unexpected modifications.
- Deploy the provided webserver detection rule to identify attempted code injection via form submission tasks.
Immediate actions
Upgrade Balbooa Forms to version 2.4.3.4 or higher
Audit forms for PHP-after-submission actions and remove shortcode usage
Threat Hunt
Search web server logs for POST requests to index.php with task=form.message containing suspicious PHP syntax
Data: Web server access logs with POST body logging
Mitigations
Upgrade to Balbooa Forms 2.4.3.4+
CVE-2026-102425
Detection coverage 1
Detect CVE-2026-102425 Exploitation - Code Injection in Balbooa Forms
criticalDetects HTTP POST requests to the Balbooa Forms task=form.message endpoint containing shell metacharacters or PHP syntax indicative of shortcode injection exploitation
Detection queries are available on the platform. Get full rules →