nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-47930 CVE-2021-47930
HIGH
Balbooa Joomla Forms Builder 2.0.6 SQL Injection Unauthenticated
Record summary
CVE-2021-47930 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit.
Description
Balbooa Joomla Forms Builder 2.0.6 contains an unauthenticated SQL injection vulnerability in the form submission handler that allows remote attackers to execute arbitrary SQL queries. Attackers can send POST requests to the com_baforms component with malicious JSON payloads in the 'id' field parameter to extract sensitive database information.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated May 12, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Balbooa Joomla Forms BuilderBrowse Balbooa / Balbooa Joomla Forms Builder | CVE List | 2.0.6 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBBalbooa Joomla Forms Builder 2.0.6 - SQL Injection (Unauthenticated)ExploitDB exploitby blockomat2100Not analyzed1 file
References
4Official Product Homepageproduct
https://www.balbooa.com/ ExploitDB-50447exploit
https://www.exploit-db.com/exploits/50447 VulnCheck Advisory: Balbooa Joomla Forms Builder 2.0.6 SQL Injection UnauthenticatedThird-party advisory
https://www.vulncheck.com/advisories/balbooa-joomla-forms-builder-sql-injection-unauthenticated