VYPR

SP Page Builder

by Joomla

CVEs (14)

  • CVE-2026-48908CriKEVJun 20, 2026
    risk 0.83cvss 9.8epss 0.15

    A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.

  • CVE-2026-67285CriAug 12, 2026
    risk 0.60cvss epss 0.00

    Joomla Extension - joomshaper.com - Unauthenticated arbitrary local PHP file inclusion in SP Page Builder < 6.8.0 - An unauthenticated attacker can perform includes to arbitrary PHP files that are accessible by the system.

  • CVE-2026-65876CriJul 27, 2026
    risk 0.60cvss epss 0.00

    Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.8.0 - Improper validation of catid parameters in the loadMoreArticles endpoint leads to an SQL injection vector.

  • CVE-2026-66494HigAug 7, 2026
    risk 0.57cvss epss 0.00

    Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Shapes API endpoint SP Page Builder < 6.7.0 - An unauthenticated attacker can store malicious JavaScript in a Joomla site's database via a single HTTP request. When an administrator opens the SP Page Builder…

  • CVE-2026-78375HigSep 14, 2026
    risk 0.56cvss epss 0.00

    Joomla Extension - joomshaper.com - Authenticated Privileged SQL Injection in the Content Plugin of SP Page Builder (Free and Pro) 5.2.1 - 6.9.0 - plgContentSppagebuilder::onContentAfterSave() read jform[attribs][sppagebuilder_article_id] from the request and concatenated it…

  • CVE-2026-81564HigSep 14, 2026
    risk 0.46cvss epss 0.00

    Joomla Extension - joomshaper.com - Missing Directory Confinement in Media Rename Allowing Arbitrary File Rename in SP Page Builder (Free and Pro) 4.0.0 - 6.9.0 - The media rename task applied neither of the directory boundary checks used by the folder operations in the same…

  • CVE-2026-81565MedSep 14, 2026
    risk 0.45cvss epss 0.00

    Joomla Extension - joomshaper.com - Missing Directory Confinement in Media Upload in SP Page Builder (Free and Pro) 4.0.0 - 6.9.0 - The folder request parameter replaced the generated date-based destination folder in its entirety and was then passed to Folder::create() and…

  • CVE-2026-67287MedAug 12, 2026
    risk 0.41cvss epss 0.00

    Joomla Extension - joomshaper.com - Unauthenticated comment creation in SP Page Builder < 6.8.0 - An unauthenticated attacker can create comments on instances with disabled guest commenting by overriding the setting in question with user supplied input.

  • CVE-2026-67286MedAug 12, 2026
    risk 0.41cvss epss 0.00

    Joomla Extension - joomshaper.com - Unauthenticated arbitrary directory creation and file write in SP Page Builder < 6.8.0 - An unauthenticated attacker can create arbitrary directories and files with a predefined name.

  • CVE-2026-81566MedSep 14, 2026
    risk 0.33cvss epss 0.00

    Joomla Extension - joomshaper.com - Missing Access Control in Menu Item Creation in SP Page Builder (Free and Pro) 4.0.0 - 6.9.0 - The add-to-menu routine invoked the com_menus item model's save() method directly. That model does not perform authorisation itself, because the…

  • CVE-2026-65879CriJul 27, 2026
    risk 0.00cvss 9.8epss 0.00

    Joomla Extension - joomshaper.com - Unauthenticated mail relay via a hardcoded, product-wide secret in SP Page Builder < 6.7.1 - A hardcoded secret allowed attackers to forge the mail from address of forms.

  • CVE-2026-65878HigJul 27, 2026
    risk 0.00cvss epss 0.00

    Joomla Extension - joomshaper.com - Authenticated arbitrary file delete in SP Page Builder < 6.7.1- Improper path validation and ACL checks lead to a file deletion vector in the media manager.

  • CVE-2026-65877HigJul 27, 2026
    risk 0.00cvss epss 0.00

    Joomla Extension - joomshaper.com - Authenticated SQL injection in SP Page Builder < 6.7.1 - Improper validation of various parameters in the media manager search and date filters lead to an SQL injection vector.

  • CVE-2026-65766CriJul 27, 2026
    risk 0.00cvss epss 0.00

    Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.7.1 - Improper validation of order parameters in the Dynamic Content endpoint leads to an SQL injection vector.