Unauthenticated SQL Injection in SP Page Builder by Joomla Extensions
CVE-2026-65876
9.2CRITICAL
What is CVE-2026-65876?
A vulnerability exists in the SP Page Builder for Joomla that allows unauthenticated attackers to exploit improper validation of 'catid' parameters in the loadMoreArticles endpoint. This security flaw can lead to unauthorized SQL injection attacks, allowing attackers to manipulate database queries and potentially access sensitive data.
Affected Version(s)
SP Page Builder extension for Joomla 1.0.0-6.7.0
