Unrated severityNVD Advisory· Published Jul 27, 2026· Updated Jul 28, 2026
Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.7.1
CVE-2026-65876
Description
Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.7.1 - Improper validation of catid parameters in the loadMoreArticles endpoint leads to an SQL injection vector.
Affected products
2- Range: <6.7.1
- Range: <6.7.1
Patches
Vulnerability mechanics
References
1- www.joomshaper.com/page-buildermitreproduct
News mentions
0No linked articles in our index yet.