Authenticated Arbitrary File Deletion in SP Page Builder by JoomShaper
CVE-2026-65878
8.3HIGH
What is CVE-2026-65878?
The SP Page Builder, a widely used Joomla extension developed by JoomShaper, is susceptible to an authenticated arbitrary file deletion vulnerability. This issue arises from improper path validation and insufficient access control list (ACL) checks, allowing unauthorized users with valid credentials to delete files through the media manager. This weakness could lead to significant data loss and manipulation, posing a severe risk to Joomla sites relying on this extension. Users are urged to upgrade to version 6.7.1 or later to mitigate this vulnerability.
Affected Version(s)
SP Page Builder extension for Joomla 1.0.0-6.7.0
