VYPR
Vendor

JoomShaper

Products
6
CVEs
17
Across products
17
Status
Private

Products

6

Recent CVEs

17
  • CVE-2026-48908CriKEVJun 20, 2026
    risk 0.83cvss 9.8epss 0.15

    A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.

  • CVE-2026-48909CriJun 20, 2026
    risk 0.65cvss epss 0.05

    SP LMS (com_splms) < 4.1.4 by JoomShaper deserializes user-controlled cookie data without validation, enabling an unauthenticated remote attacker to execute arbitrary code on the server.

  • CVE-2026-66494HigAug 7, 2026
    risk 0.57cvss epss 0.00

    Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Shapes API endpoint SP Page Builder < 6.7.0 - An unauthenticated attacker can store malicious JavaScript in a Joomla site's database via a single HTTP request. When an administrator opens the SP Page Builder…

  • CVE-2026-78302HigSep 10, 2026
    risk 0.56cvss epss 0.00

    Joomla Extension - joomshaper.com - Unauthenticated Stored Cross-Site Scripting (XSS) via Unescaped Output in Views and Admin Lists in SP Property < 4.1.4 - Multiple template files across frontend views and administrator list tables rendered attributes and text values directly…

  • CVE-2026-79701MedSep 14, 2026
    risk 0.45cvss epss 0.00

    Joomla Extension - joomshaper.com - Unauthenticated CAPTCHA Bypass in Module Context in the Contact, Opt-in and Form Builder Addons in SP Page Builder Pro 3.2.6 - 6.9.0 - In the ajax_contact, optin_form and form_builder addons, the result returned by the CAPTCHA plugin's…

  • CVE-2026-79700MedSep 14, 2026
    risk 0.45cvss epss 0.00

    Joomla Extension - joomshaper.com - Unauthenticated CAPTCHA Bypass via Request-Controlled CAPTCHA Configuration in SP Page Builder Pro 5.1.4 - 6.9.0 - The optin_form addon read the CAPTCHA type, the expected answer and the enabled flag from the request rather than from the…

  • CVE-2026-78085MedSep 10, 2026
    risk 0.45cvss epss 0.00

    Joomla Extension - joomshaper.com - Path Traversal in Gallery Image Management in SP Property < 4.1.4 - The gallery management controller tasks lacked directory confinement checks.

  • CVE-2026-78303MedSep 10, 2026
    risk 0.45cvss epss 0.00

    Joomla Extension - joomshaper.com - Unvalidated Email Destination & Form Manipulation in Booking Requests in SP Property < 4.1.4 - Booking inquiries previously relied on client-submitted hidden fields for recipient routing, allowing potential email manipulation.

  • CVE-2026-78084MedSep 10, 2026
    risk 0.45cvss epss 0.00

    Joomla Extension - joomshaper.com - Missing Access Control in Gallery Image Management in SP Property < 4.1.4 - The gallery management controller tasks lacked authorization checks and CSRF token validation.. Users could invoke file removal actions with arbitrary path strings or…

  • CVE-2026-67287MedAug 12, 2026
    risk 0.41cvss epss 0.00

    Joomla Extension - joomshaper.com - Unauthenticated comment creation in SP Page Builder < 6.8.0 - An unauthenticated attacker can create comments on instances with disabled guest commenting by overriding the setting in question with user supplied input.

  • CVE-2026-81566MedSep 14, 2026
    risk 0.33cvss epss 0.00

    Joomla Extension - joomshaper.com - Missing Access Control in Menu Item Creation in SP Page Builder (Free and Pro) 4.0.0 - 6.9.0 - The add-to-menu routine invoked the com_menus item model's save() method directly. That model does not perform authorisation itself, because the…

  • CVE-2026-65879CriJul 27, 2026
    risk 0.00cvss 9.8epss 0.00

    Joomla Extension - joomshaper.com - Unauthenticated mail relay via a hardcoded, product-wide secret in SP Page Builder < 6.7.1 - A hardcoded secret allowed attackers to forge the mail from address of forms.

  • CVE-2026-65878HigJul 27, 2026
    risk 0.00cvss epss 0.00

    Joomla Extension - joomshaper.com - Authenticated arbitrary file delete in SP Page Builder < 6.7.1- Improper path validation and ACL checks lead to a file deletion vector in the media manager.

  • CVE-2026-65877HigJul 27, 2026
    risk 0.00cvss epss 0.00

    Joomla Extension - joomshaper.com - Authenticated SQL injection in SP Page Builder < 6.7.1 - Improper validation of various parameters in the media manager search and date filters lead to an SQL injection vector.

  • CVE-2026-65766CriJul 27, 2026
    risk 0.00cvss epss 0.00

    Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.7.1 - Improper validation of order parameters in the Dynamic Content endpoint leads to an SQL injection vector.

  • CVE-2026-65760CriJul 23, 2026
    risk 0.00cvss epss 0.00

    Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0.0-2.0.1 - Improper access checks allow logged in users to retreive order and customer information of any order in the system.

  • CVE-2026-57829MedJul 13, 2026
    risk 0.00cvss 6.1epss 0.00

    Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Helix Ultimate < 2.2.7 - The Joomla extension Helix Ultimate is vulnerable to an unauthenticated stored XSS.