VYPR

SP Page Builder

by Joomla

CVEs (5)

  • CVE-2026-65876Jul 27, 2026
    risk 0.00cvss epss 0.00

    Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.7.1 - Improper validation of catid parameters in the loadMoreArticles endpoint leads to an SQL injection vector.

  • CVE-2026-65877Jul 27, 2026
    risk 0.00cvss epss 0.00

    Joomla Extension - joomshaper.com - Authenticated SQL injection in SP Page Builder < 6.7.1 - Improper validation of various parameters in the media manager search and date filters lead to an SQL injection vector.

  • CVE-2026-65879Jul 27, 2026
    risk 0.00cvss epss 0.00

    Joomla Extension - joomshaper.com - Unauthenticated mail relay via a hardcoded, product-wide secret in SP Page Builder < 6.7.1 - A hardcoded secret allowed attackers to forge the mail from address of forms.

  • CVE-2026-65766Jul 27, 2026
    risk 0.00cvss epss 0.00

    Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.7.1 - Improper validation of order parameters in the Dynamic Content endpoint leads to an SQL injection vector.

  • CVE-2026-65878Jul 27, 2026
    risk 0.00cvss epss 0.00

    Joomla Extension - joomshaper.com - Authenticated arbitrary file delete in SP Page Builder < 6.7.1- Improper path validation and ACL checks lead to a file deletion vector in the media manager.