Access Control Flaw in SP Property by JoomShaper
CVE-2026-78084

6.9MEDIUM

Key Information:

Vendor
CVE Published:
10 September 2026

What is CVE-2026-78084?

The SP Property extension by JoomShaper suffers from a missing access control vulnerability in its gallery image management features. This issue allows authenticated users to execute file removal actions without proper authorization checks or CSRF token validation. Consequently, an attacker could potentially manipulate file paths to delete arbitrary files or upload malicious file types, posing significant risks to the integrity of the website.

Affected Version(s)

SP Property extension for Joomla 1.0.0-4.1.3

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.