Balbooa Forms versions earlier than 2.4.3.4 for Joomla contain a code-injection vulnerability in the PHP-after-submission action. The extension allows administrators to define PHP executed after a public form submission and supports form-field shortcodes in that PHP. Before evaluating the PHP, the component substitutes each shortcode with the visitor's unescaped submitted value. If an attacker-controlled shortcode is interpolated into a double-quoted PHP string, an unauthenticated attacker can inject and execute arbitrary PHP code.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This five-file standalone Python repository implements a Tkinter GUI scanner and exploit tool for the claimed CVE-2026-102425 in Balbooa Forms (Joomla com_baforms). `main.py` is the sole code file and entry point; it uses requests/urllib3 for HTTPS requests with certificate verification disabled, supports a single target or a mass URL list, concurrent processing, colored GUI logging, CSV export, and automatic `hits.txt`/`exploited.txt` outputs. Detection fetches the site root, identifies com_baforms indicators and public form IDs, probes the `form.loadAjaxForm` task, and queries three XML manifest locations to determine whether the version is below 2.4.3.4. Exploitation is more than detection: it uses a double-quote/semicolon shortcode breakout to execute PHP and validate execution through `BAF-102425-CONFIRM`; its optional second stage writes and checks `up.php`, a PHP uploader marked by `BAF-102425-SHELL-OK`. The program also contains a local mock LAB TEST facility intended to simulate the shortcode-evaluation path without contacting a real host. No recognized exploit framework is used; this is a purpose-built GUI application with a hardcoded, basic PHP payload, so its maturity is assessed as OPERATIONAL.
This is a standalone Python 3 exploit repository for CVE-2026-102425 in the Joomla Balbooa Forms com_baforms extension. The principal implementation is _engine.py, while poc.py provides an interactive and simplified mass-operation wrapper. The code checks component manifests and public pages for affected versions and exposed forms, then submits malicious field values to Balbooa form handlers. Exploitation depends on a pre-existing vulnerable PHP-after-submission configuration that interpolates a field shortcode within a double-quoted PHP string before eval(). On successful code execution, it attempts to deploy the bundled up.php PHP multipart file uploader to several common Joomla paths and records accessible shell URLs. targets.example.txt contains example target-list input, and README.md documents detection, exploitation, optional CVE-2026-67364 testing, and remediation. The included up.php is a basic unauthenticated file uploader; although it declares an auth-related variable, it does not enforce authentication.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.