What the vulnerability does
01Description
Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Shapes API endpoint SP Page Builder < 6.7.0 - An unauthenticated attacker can store malicious JavaScript in a Joomla site's database via a single HTTP request. When an administrator opens the SP Page Builder editor, the JavaScript executes in their browser automatically..
Explanation of Vulnerability in Simple Terms
02Summary
SP Page Builder for Joomla contains an access control flaw that allows unauthenticated attackers to perform unauthorized actions via the network. The vulnerability requires user interaction and affects confidentiality, integrity, and availability of the site. Update to a version newer than 1.0.0-6.6.2 when available.
What an attacker can do
03Attacker Capabilities
Perform unauthorized actions on the site without authentication, potentially affecting data confidentiality and integrity.
Potential impact on your site
04Site Impact
Unauthorized users can access or modify site content and functionality through SP Page Builder without logging in.
Conditions required to exploit
05Prerequisites
Network access and user interaction (victim must click a link or visit a page).
Key dates
06Disclosure timeline
August 7, 2026
CVE published
August 7, 2026
Record updated