Reflected XSS Vulnerability in SP Page Builder Pro by JoomShaper
CVE-2026-102426
5.3MEDIUM
What is CVE-2026-102426?
In the SP Page Builder Pro add-on by JoomShaper, a reflected XSS vulnerability allows an unauthenticated attacker to manipulate rendered pages. The vulnerability arises from improper handling of the 'dc_filter_' request parameter, where the slider values are echoed as text without adequate escaping. This flaw can lead to the injection of arbitrary HTML or JavaScript, enabling attackers to execute malicious scripts in the context of a user's browser, potentially compromising user data and session integrity.
Affected Version(s)
SP Page Builder (Pro) extension for Joomla 3.0.0 - 5.6.1p2
