Description
Joomla Extension - joomshaper.com - Unauthenticated arbitrary local PHP file inclusion in SP Page Builder < 6.8.0 - An unauthenticated attacker can perform includes to arbitrary PHP files that are accessible by the system.
Published: 2026-08-12
Score: 9.2 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an unauthenticated attacker to trigger the SP Page Builder extension for Joomla to include arbitrary local PHP files that are accessible to the system. This Local File Inclusion flaw (CWE-22) could enable an attacker to read sensitive files on the web server or execute PHP code if the attacker can influence the contents of the included file. The description does not confirm the ability to upload or otherwise weaponize files, so while the risk is significant, remote code execution is not explicitly stated.

Affected Systems

Joomla sites that host the SP Page Builder extension from joomshaper.com with a version earlier than 6.8.0 are affected. The flaw exists only in these older releases, so sites using 6.8.0 or later are not impacted.

Risk and Exploitability

The CVSS score of 9.2 indicates a high severity flaw. No EPSS score is provided, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is web‑based and requires no authentication, meaning anyone who can send a request to a vulnerable site can exploit the inclusion. Because the flaw permits access to any local PHP file, the potential impact on confidentiality, integrity, and availability is severe, but the exact exploitation probability cannot be quantified from the current data.

Generated by OpenCVE AI on August 13, 2026 at 01:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the SP Page Builder extension to version 6.8.0 or later.
  • If upgrading is not immediately possible, disable or remove the SP Page Builder extension to eliminate the inclusion entry point.
  • Review the web root for unnecessary PHP files, remove them, and set restrictive file permissions to prevent unauthorized access.

Generated by OpenCVE AI on August 13, 2026 at 01:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Thu, 13 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Joomshaper.net
Joomshaper.net sp Page Builder Extension For Joomla
Vendors & Products Joomshaper.net
Joomshaper.net sp Page Builder Extension For Joomla

Wed, 12 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 12 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Description Joomla Extension - joomshaper.com - Unauthenticated arbitrary local PHP file inclusion in SP Page Builder < 6.8.0 - An unauthenticated attacker can perform includes to arbitrary PHP files that are accessible by the system.
Title Joomla Extension - joomshaper.com - Unauthenticated arbitrary local PHP file inclusion in SP Page Builder < 6.8.0
Weaknesses CWE-22
References
Metrics cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Joomshaper.net Sp Page Builder Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-08-14T19:09:13.060Z

Reserved: 2026-07-29T12:45:20.369Z

Link: CVE-2026-67285

cve-icon Vulnrichment

Updated: 2026-08-12T14:15:07.910Z

cve-icon NVD

Status : Deferred

Published: 2026-08-12T14:18:33.423

Modified: 2026-08-26T16:36:16.990

Link: CVE-2026-67285

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T10:15:07Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')