Description
Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Shapes API endpoint SP Page Builder < 6.7.0 - An unauthenticated attacker can store malicious JavaScript in a Joomla site's database via a single HTTP request. When an administrator opens the SP Page Builder editor, the JavaScript executes in their browser automatically..
Published: 2026-08-07
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated attacker can submit malicious JavaScript to the Shapes API endpoint of the SP Page Builder extension for Joomla. The payload is stored in the site database and executes automatically in the browser when an administrator opens the editor, enabling the attacker to hijack admin sessions, exfiltrate credentials, or deface the site.

Affected Systems

The vulnerability affects the SP Page Builder extension provided by joomshaper.com for Joomla, specifically any installation running a version earlier than 6.7.0.

Risk and Exploitability

The CVSS score of 8.7 indicates a high severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. An unauthenticated attacker can trigger the flaw simply by sending a crafted HTTP request to the endpoint; no further credentials or permissions are required, making exploitation straightforward for anyone with network access to the site.

Generated by OpenCVE AI on August 7, 2026 at 14:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest update for SP Page Builder, version 6.7.0 or newer, directly from joomshaper.com
  • Remove any stored malicious JavaScript payloads that may remain in the database after the upgrade
  • Implement input validation or a whitelist for the Shapes API endpoint to ensure only safe content is stored

Generated by OpenCVE AI on August 7, 2026 at 14:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Sat, 08 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Joomshaper.net
Joomshaper.net sp Page Builder Extension For Joomla
Vendors & Products Joomshaper.net
Joomshaper.net sp Page Builder Extension For Joomla

Fri, 07 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 07 Aug 2026 13:15:00 +0000

Type Values Removed Values Added
Description Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Shapes API endpoint SP Page Builder < 6.7.0 - An unauthenticated attacker can store malicious JavaScript in a Joomla site's database via a single HTTP request. When an administrator opens the SP Page Builder editor, the JavaScript executes in their browser automatically..
Title Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Shapes API endpoint SP Page Builder < 6.7.0
Weaknesses CWE-284
CWE-79
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Joomshaper.net Sp Page Builder Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-08-10T09:48:53.889Z

Reserved: 2026-07-27T13:01:42.270Z

Link: CVE-2026-66494

cve-icon Vulnrichment

Updated: 2026-08-07T14:50:43.794Z

cve-icon NVD

Status : Deferred

Published: 2026-08-07T13:16:52.827

Modified: 2026-08-26T16:36:16.990

Link: CVE-2026-66494

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-08T20:53:11Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')