Reflected XSS Vulnerability in SP Page Builder Pro by JoomShaper
CVE-2026-102426

5.3MEDIUM

Key Information:

Vendor
CVE Published:
5 October 2026

What is CVE-2026-102426?

In the SP Page Builder Pro add-on by JoomShaper, a reflected XSS vulnerability allows an unauthenticated attacker to manipulate rendered pages. The vulnerability arises from improper handling of the 'dc_filter_' request parameter, where the slider values are echoed as text without adequate escaping. This flaw can lead to the injection of arbitrary HTML or JavaScript, enabling attackers to execute malicious scripts in the context of a user's browser, potentially compromising user data and session integrity.

Affected Version(s)

SP Page Builder (Pro) extension for Joomla 3.0.0 - 5.6.1p2

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Phil Taylor, mysites.guru
.