VYPR
Vypr IntelligenceAI-generatedSep 10, 2026· 6 CVEs

Joomla Extensions SP Property & T4 Page Builder: Six Vulnerabilities Disclosed Together

Six vulnerabilities, including critical SQL injection and XSS, were disclosed for Joomla extensions SP Property and T4 Page Builder on September 10, 2026.

Key findings

  • Six vulnerabilities disclosed on September 10, 2026, affect Joomla extensions SP Property and T4 Page Builder.
  • Critical SQL injection (CVE-2026-78082) and XSS (CVE-2026-78082) flaws in SP Property allow unauthenticated data compromise and script execution.
  • Missing CSRF protection in SP Property (CVE-2026-78083) enables unauthorized actions via booking and contact forms.
  • Path traversal (CVE-2026-78085) and email manipulation (CVE-2026-78303) vulnerabilities also impact SP Property.
  • T4 Page Builder suffers from an open mail relay vulnerability (CVE-2026-78374).
  • All SP Property vulnerabilities are patched in version 4.1.4; update immediately.

On September 10, 2026, a batch of six vulnerabilities was disclosed across two popular Joomla extensions: SP Property by JoomShaper and T4 Page Builder by Joomla- pemasaran. The disclosures, occurring within a one-hour window, include a critical SQL injection flaw, two high-severity issues (XSS and missing CSRF verification), and three medium-severity bugs. These vulnerabilities collectively expose Joomla sites to risks ranging from data breaches and site defacement to unauthorized actions and information disclosure.

The most severe vulnerability, CVE-2026-78082, is an unauthenticated SQL injection flaw in SP Property (versions prior to 4.1.4). This allows attackers to inject malicious SQL code into property search and map filtering functionalities, potentially leading to the compromise of sensitive database information.

Further compounding the risk for SP Property users, CVE-2026-78083 highlights a critical security oversight: missing CSRF token verification. This affects the visitor booking and agent contact form submission endpoints, enabling unauthenticated attackers to perform unauthorized actions, such as submitting fake bookings or contacting agents without proper authorization. Additionally, CVE-2026-78082, also impacting SP Property, is an unauthenticated stored Cross-Site Scripting (XSS) vulnerability. This flaw arises from unescaped output in various frontend views and administrator lists, allowing attackers to inject malicious scripts that can execute in the browsers of other users, potentially leading to session hijacking or credential theft.

Medium-severity issues were also identified in SP Property. CVE-2026-78085 involves a path traversal vulnerability in the gallery image management feature, enabling attackers to access or manipulate files outside the intended directory. CVE-2026-78303 points to unvalidated email destinations and form manipulation in booking requests, allowing potential manipulation of booking inquiry routing.

The T4 Page Builder extension is affected by CVE-2026-78374, an open mail relay vulnerability via its contact AJAX endpoint. This unauthenticated endpoint lacks proper security checks, enabling attackers to send emails through the affected server, potentially for spamming or phishing campaigns.

All identified vulnerabilities in SP Property are fixed in version 4.1.4. Users of these extensions are strongly advised to update immediately to mitigate the risks associated with these critical security flaws. The coordinated disclosure of these vulnerabilities underscores the importance of timely patching for Joomla extensions to maintain website security.

The clustered release of these vulnerabilities highlights a significant security posture issue within these popular Joomla extensions, demanding immediate attention from administrators to secure their websites against potential exploitation.

Key Findings

  • Six vulnerabilities disclosed on September 10, 2026, affect Joomla extensions SP Property and T4 Page Builder.
  • Critical SQL injection (CVE-2026-78082) and XSS (CVE-2026-78082) flaws in SP Property allow unauthenticated data compromise and script execution.
  • Missing CSRF protection in SP Property (CVE-2026-78083) enables unauthorized actions via booking and contact forms.
  • Path traversal (CVE-2026-78085) and email manipulation (CVE-2026-78303) vulnerabilities also impact SP Property.
  • T4 Page Builder suffers from an open mail relay vulnerability (CVE-2026-78374).
  • All SP Property vulnerabilities are patched in version 4.1.4; update immediately.
AI-written article. Grounded in 6 CVE records listed below.