<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>WildforTech Security Advisories — Balbooa</title><description>Actively exploited vulnerabilities affecting Balbooa products.</description><link>https://wildfortech.com</link><atom:link href="https://wildfortech.com/security/vendor/balbooa.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-56291 — Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability</title><link>https://wildfortech.com/security#CVE-2026-56291</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2026-56291</guid><description>This vulnerability in Balbooa Forms allows anyone — without logging in — to upload executable files to a affected system. Because there are no authentication checks blocking dangerous file types, an attacker can follow up by running that uploaded code on the server, achieving full remote code execution. This effectively hands an unauthenticated outsider complete control over the underlying system, making it a critical risk for any internet-facing deployment of the product.</description><pubDate>Fri, 10 Jul 2026 00:00:00 GMT</pubDate><category>Balbooa</category><category>Forms</category></item></channel></rss>