Description
Joomla Extension - joomshaper.com - Authenticated SQL injection in SP Page Builder < 6.7.1 - Improper validation of various parameters in the media manager search and date filters lead to an SQL injection vector.
Published: 2026-07-27
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an authenticated SQL injection that allows an actor with valid Joomla credentials to manipulate database queries through the SP Page Builder extension’s media manager search and date filter parameters. By injecting crafted input, an attacker can read, modify, or delete database records, potentially compromising site content, user data, or administrative settings. The weakness is a classic input validation flaw as specified by CWE-89.

Affected Systems

The affected product is the SP Page Builder extension for Joomla published by joomshaper.com. Versions prior to 6.7.1 are susceptible; no other version information is available in the report.

Risk and Exploitability

The CVSS score of 8.2 highlights a high severity, and the EPSS score of 0.00226 indicates a very low but non‑zero exploitation probability. The lack of KEV listing does not diminish the risk for environments running the vulnerable extension. As an attacker must be authenticated, the likelihood of exploitation depends on the attacker’s ability to acquire valid credentials. Once authenticated, the injection can be performed via the media manager interface leading to potential data tampering or exfiltration.

Generated by OpenCVE AI on August 3, 2026 at 17:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the SP Page Builder extension to version 6.7.1 or later.
  • If an upgrade is not immediately possible, remove or restrict access to the media manager functionality to trusted users only, or apply temporary input sanitization to the relevant parameters.
  • Audit database permissions and monitor for unexpected changes to table data, ensuring that only authorized users have write access to critical tables.

Generated by OpenCVE AI on August 3, 2026 at 17:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Joomshaper.net
Joomshaper.net sp Page Builder Extension For Joomla
Vendors & Products Joomshaper.net
Joomshaper.net sp Page Builder Extension For Joomla

Mon, 27 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Description Joomla Extension - joomshaper.com - Authenticated SQL injection in SP Page Builder < 6.7.1 - Improper validation of various parameters in the media manager search and date filters lead to an SQL injection vector.
Title Joomla Extension - joomshaper.com - Authenticated SQL injection in SP Page Builder < 6.7.1
Weaknesses CWE-89
References
Metrics cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N'}


Subscriptions

Joomshaper.net Sp Page Builder Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-08-12T13:54:08.527Z

Reserved: 2026-07-23T09:17:01.409Z

Link: CVE-2026-65877

cve-icon Vulnrichment

Updated: 2026-07-27T17:04:09.836Z

cve-icon NVD

Status : Deferred

Published: 2026-07-27T14:17:00.823

Modified: 2026-07-27T21:17:16.347

Link: CVE-2026-65877

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T17:45:03Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')