Description
Joomla Extension - joomshaper.com - Authenticated Privileged SQL Injection in the Content Plugin of SP Page Builder (Free and Pro) 5.2.1 - 6.9.0 - plgContentSppagebuilder::onContentAfterSave() read jform[attribs][sppagebuilder_article_id] from the request and concatenated it directly into the WHERE view_id = ... clause of a query against #__sppagebuilder without quoting or type casting. Joomla's ARRAY input filter does not sanitise element values, as InputFilter::clean() returns (array) $source with the elements untouched, so the entire payload could be delivered in a single POST field. The affected block also executed before the com_content.article context test, so it ran on every onContentAfterSave event regardless of which component triggered the save. An attacker could perform time-based blind SQL injection to read arbitrary database contents, including the #__users and #__session tables.
Published: 2026-09-14
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Authenticated Privileged SQL Injection allowing unauthorized database read
Action: Immediate Patch
AI Analysis

Impact

An authenticated Joomla user can exploit a SQL injection flaw in the SP Page Builder extension’s content plugin. The plugin reads the sppagebuilder_article_id field from the request and concatenates it directly into a WHERE clause without sanitization read arbitrary database tables, including the users and session tables, thereby compromising user credentials and session data.

Affected Systems

Versions of the SP Page Builder (Free and Pro) extension for Joomla from 5.2.1 through 6.9.0 are affected.

Risk and Exploitability

The flaw receives a CVSS score of 8.6, indicating high severity. EPSS data are not available, and the vulnerability is not listed in the CISA KEV catalog. The vulnerability operation, as the code executes on every onContentAfterSave event regardless of the component that triggered it. Because the injection is time‑based and blind, an attacker does not need direct access to the database but can retrieve sensitive data through response timing. The attack can be carried out in a normal administrative or editorial context, making it a significant threat to sites running the affected plugin.

Generated by OpenCVE AI on September 15, 2026 at 14:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the SP Page Builder extension to the latest available version (>=6.9.1 or newer) where the injection vulnerability has been fixed.
  • If an update is unavailable, temporarily disable the SP Page Builder content plugin to prevent the vulnerable code from executing during content saves.
  • Restrict Joomla user roles only trusted administrators, reducing the number of accounts that can trigger the vulnerability.

Generated by OpenCVE AI on September 15, 2026 at 14:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
Description Joomla Extension - joomshaper.com - Authenticated Privileged SQL Injection in the Content Plugin of SP Page Builder (Free and Pro) 5.2.1 - 6.9.0 - plgContentSppagebuilder::onContentAfterSave() read jform[attribs][sppagebuilder_article_id] from the request and concatenated it directly into the WHERE view_id = ... clause of a query against #__sppagebuilder without quoting or type casting. Joomla's ARRAY input filter does not sanitise element values, as InputFilter::clean() returns (array) $source with the elements untouched, so the entire payload could be delivered in a single POST field. The affected block also executed before the com_content.article context test, so it ran on every onContentAfterSave event regardless of which component triggered the save. An attacker could perform time-based blind SQL injection to read arbitrary database contents, including the #__users and #__session tables.
Title Joomla Extension - joomshaper.com - Authenticated Privileged SQL Injection in the Content Plugin of SP Page Builder (Free and Pro) 5.2.1 - 6.9.0
Weaknesses CWE-89
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-09-15T04:43:59.377Z

Reserved: 2026-08-24T13:12:10.196Z

Link: CVE-2026-78375

cve-icon Vulnrichment

Updated: 2026-09-14T14:25:41.094Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T11:17:04.430

Modified: 2026-09-16T19:28:06.713

Link: CVE-2026-78375

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T14:30:08Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')