What the vulnerability does
01Description
Joomla Extension - joomshaper.com - Authenticated SQL injection in SP Page Builder < 6.7.1 - Improper validation of various parameters in the media manager search and date filters lead to an SQL injection vector.
Explanation of Vulnerability in Simple Terms
02Summary
SP Page Builder for Joomla contains a SQL injection vulnerability in versions 1.0.0 through 6.7.0. An attacker with high-level administrator privileges can inject malicious SQL commands through the extension's input fields. This allows reading or modifying database contents, including user credentials and site configuration. Sites running affected versions should update immediately.
What an attacker can do
03Attacker Capabilities
Read or modify the Joomla database, including user accounts and site configuration.
Potential impact on your site
04Site Impact
A compromised admin account could expose all site data or allow further site takeover.
Conditions required to exploit
05Prerequisites
Attacker must have high-level administrator access to the Joomla site.
Key dates
06Disclosure timeline
July 27, 2026
CVE published