Live This site runs Joomla 6.1.2
JoomClub

News, security and craft for the Joomla ecosystem

Security

Gridbox 2.20.4.0 fixes Joomla security flaws

Balbooa has released Gridbox 2.20.4.0 for Joomla, fixing a high-severity CSRF vulnerability in language installation and a separate image path validation weakness.

The affected releases are Gridbox 2.20.2 through 2.20.3.1. The CSRF issue could allow an attacker to induce a logged-in Joomla Super User to install a package through the component. The image preview issue could accept paths outside Gridbox’s configured media folder, although the affected function served image files rather than PHP files.

mySites.guru published the analysis and rated the overall release High because successful exploitation of the CSRF flaw could result in attacker-selected software being installed. The image preview issue was assessed as Low on its own. The write-up does not report exploitation of either issue. No CVE identifiers or CVSS score had been assigned as of 8 October 2026.

Administrators should update every affected installation to Gridbox 2.20.4.0 and confirm the installed version afterward. Sites running versions below 2.20.2 may also be exposed to earlier, actively exploited Gridbox vulnerabilities and should be updated urgently, with checks for unexpected extensions and administrator accounts.

Originally reported by mySites.guru.