Unrated severityNVD Advisory· Published Jul 27, 2026· Updated Jul 28, 2026
Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.7.1
CVE-2026-65766
Description
Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.7.1 - Improper validation of order parameters in the Dynamic Content endpoint leads to an SQL injection vector.
Affected products
2- Range: <6.7.1
- Range: <6.7.1
Patches
Vulnerability mechanics
References
2- mysites.guru/blog/sp-page-builder-sql-injection-mail-relay-disclosure/mitrethird-party-advisory
- www.joomshaper.com/page-buildermitreproduct
News mentions
0No linked articles in our index yet.