CVE-2026-66494 HIGH

CVE-2026-66494: Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Shapes API endpoint SP Page Builder < 6.7.0

Vendor Joomshaper.com
Product SP Page Builder extension for Joomla
Weakness CWE-284
Published August 7, 2026
Last update August 7, 2026

CVSS base score

8.7/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Shapes API endpoint SP Page Builder < 6.7.0 - An unauthenticated attacker can store malicious JavaScript in a Joomla site's database via a single HTTP request. When an administrator opens the SP Page Builder editor, the JavaScript executes in their browser automatically..

Explanation of Vulnerability in Simple Terms

02Summary

SP Page Builder for Joomla contains an access control flaw that allows unauthenticated attackers to perform unauthorized actions via the network. The vulnerability requires user interaction and affects confidentiality, integrity, and availability of the site. Update to a version newer than 1.0.0-6.6.2 when available.

What an attacker can do

03Attacker Capabilities

Perform unauthorized actions on the site without authentication, potentially affecting data confidentiality and integrity.

Potential impact on your site

04Site Impact

Unauthorized users can access or modify site content and functionality through SP Page Builder without logging in.

Conditions required to exploit

05Prerequisites

Network access and user interaction (victim must click a link or visit a page).

Key dates

06Disclosure timeline

August 7, 2026 CVE published
August 7, 2026 Record updated

Related vulnerabilities

08Related CVE