Unauthenticated SQL Injection Vulnerability in Joomla Extension SP Property by JoomShaper
CVE-2026-78082

9.3CRITICAL

Key Information:

Vendor
CVE Published:
10 September 2026

What is CVE-2026-78082?

The SP Property extension for Joomla by JoomShaper is vulnerable to an unauthenticated SQL injection issue. Attackers can exploit this vulnerability by manipulating the property search and map filtering functionalities, leveraging improperly constructed SQL queries. The queries are formed by directly appending user-provided parameters, resulting in the potential for executing boolean-based or time-based blind SQL injections. This could allow an attacker to extract sensitive data from the underlying database without needing authentication.

Affected Version(s)

SP Property extension for Joomla 1.0.0-4.1.3

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Phil Taylor, mysites.guru
.