Security
Critical Gridbox flaws fixed in Joomla extension update
Balbooa’s Joomla page builder Gridbox contains 23 critical vulnerabilities, including pre-authentication remote code execution. mySites.guru says some flaws are being exploited and urges an immediate update to 2.20.2.
mySites.guru disclosed the findings after Balbooa commissioned a full security review of com_gridbox. The issues affect Gridbox 2.20.1 and earlier; Balbooa released 2.20.2 on 29 July 2026 as the complete fix.
- Unauthenticated remote code execution through a single request
- Privilege escalation and routes to administrator access without a password
- Unauthenticated SQL injection, including a path that exposes user password hashes
- Unauthenticated file reading and deletion flaws
The advisory names CVE-2026-65884 and CVE-2026-65885, rated Critical at 10.0 and 9.4 respectively. Both records have the “Attacked” exploit-maturity designation. The earlier Gridbox authentication bypass, CVE-2026-61425, was fixed in 2.20.1.
The Joomla Security Strike Team has confirmed active exploitation of several issues. Administrators should install 2.20.2 immediately and check their sites, logs and user accounts for signs of compromise, including unexpected administrator accounts.
Originally reported by mySites.guru.