Description
Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.8.0 - Improper validation of catid parameters in the loadMoreArticles endpoint leads to an SQL injection vector.
Published: 2026-07-27
Score: 9.2 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the SP Page Builder extension for Joomla and manifests through improper validation of the 'catid' parameter in the loadMoreArticles endpoint. An attacker can supply malicious input to inject arbitrary SQL statements, enabling unauthorized execution of database queries that can read, modify, or delete sensitive data stored within the Joomla site's database. This type of injection can compromise the confidentiality, integrity, and availability of the site’s data and, if the database user has extensive privileges, can act as a pivot to more serious system compromise.

Affected Systems

All installations of the SP Page Builder extension for Joomla with a version earlier than 6.8.0 are affected. The extension is distributed by joomshaper.com, and any Joomla site using a pre‑6.8.0 build of this extension is vulnerable.

Risk and Exploitability

The CVSS score of 9.2 rates this flaw as critical. The EPSS score is <1%, indicating that while exploitation is unlikely, the high severity demands rapid action. The vulnerability is not listed in the CISA KEV catalog. An attacker only needs network access to the web server and can target the loadMoreArticles route directly via HTTP requests, without authentication. If exploited, the attacker could obtain or alter the site’s database contents and potentially use the database privileges to attack other parts of the infrastructure.

Generated by OpenCVE AI on August 13, 2026 at 10:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the SP Page Builder extension to version 6.8.0 or later to eliminate the injection vector
  • Restrict access to the loadMoreArticles endpoint by blocking unauthenticated requests through a web ACL or firewall if an immediate upgrade is not feasible
  • After applying the patch, monitor and review logs for evidence of injection attempts and validate that the database remains unaltered

Generated by OpenCVE AI on August 13, 2026 at 10:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Wed, 12 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Description Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.7.1 - Improper validation of catid parameters in the loadMoreArticles endpoint leads to an SQL injection vector. Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.8.0 - Improper validation of catid parameters in the loadMoreArticles endpoint leads to an SQL injection vector.
Title Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.7.1 Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.8.0

Mon, 27 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Joomshaper.net
Joomshaper.net sp Page Builder Extension For Joomla
Vendors & Products Joomshaper.net
Joomshaper.net sp Page Builder Extension For Joomla

Mon, 27 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Description Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.7.1 - Improper validation of catid parameters in the loadMoreArticles endpoint leads to an SQL injection vector.
Title Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.7.1
Weaknesses CWE-89
References
Metrics cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N'}


Subscriptions

Joomshaper.net Sp Page Builder Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-08-12T13:59:12.215Z

Reserved: 2026-07-23T09:17:01.408Z

Link: CVE-2026-65876

cve-icon Vulnrichment

Updated: 2026-07-27T17:03:20.632Z

cve-icon NVD

Status : Deferred

Published: 2026-07-27T14:17:00.680

Modified: 2026-08-12T15:18:17.010

Link: CVE-2026-65876

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T11:00:12Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')