CVE-2026-65877 HIGH

CVE-2026-65877: Joomla Extension - joomshaper.com - Authenticated SQL injection in SP Page Builder < 6.7.1

Vendor Joomshaper.com
Product SP Page Builder extension for Joomla
Weakness CWE-89 · SQLi
Published July 27, 2026
Last update July 27, 2026

CVSS base score

8.2/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N

What the vulnerability does

01Description

Joomla Extension - joomshaper.com - Authenticated SQL injection in SP Page Builder < 6.7.1 - Improper validation of various parameters in the media manager search and date filters lead to an SQL injection vector.

Explanation of Vulnerability in Simple Terms

02Summary

SP Page Builder for Joomla contains a SQL injection vulnerability in versions 1.0.0 through 6.7.0. An attacker with high-level administrator privileges can inject malicious SQL commands through the extension's input fields. This allows reading or modifying database contents, including user credentials and site configuration. Sites running affected versions should update immediately.

What an attacker can do

03Attacker Capabilities

Read or modify the Joomla database, including user accounts and site configuration.

Potential impact on your site

04Site Impact

A compromised admin account could expose all site data or allow further site takeover.

Conditions required to exploit

05Prerequisites

Attacker must have high-level administrator access to the Joomla site.

Key dates

06Disclosure timeline

July 27, 2026 CVE published

Related vulnerabilities

08Related CVE