Unauthenticated SQL Injection in Joomla Extension by JoomShaper
CVE-2026-65766

9.2CRITICAL

Key Information:

Vendor
CVE Published:
27 July 2026

What is CVE-2026-65766?

The SP Page Builder extension by JoomShaper is susceptible to an unauthenticated SQL injection vulnerability due to improper validation of order parameters in the Dynamic Content endpoint. Attackers may exploit this weakness to execute arbitrary SQL queries, potentially leading to unauthorized access and data manipulation. Users of versions prior to 6.7.1 are strongly advised to upgrade to safeguard their Joomla applications from this security issue.

Affected Version(s)

SP Page Builder extension for Joomla 1.0.0-6.7.0

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Phil Taylor
.