Path Traversal Vulnerability in SP Property by JoomShaper
CVE-2026-78085

6.9MEDIUM

Key Information:

Vendor
CVE Published:
10 September 2026

What is CVE-2026-78085?

The SP Property Joomla extension by JoomShaper has a path traversal vulnerability within its gallery image management feature. This issue arises from the lack of proper directory confinement checks in the gallery management controller. As a result, unauthorized users may exploit this vulnerability to access sensitive files on the server, potentially compromising the security of the affected system. It is crucial for users of SP Property versions earlier than 4.1.4 to apply the necessary updates to mitigate this security risk.

Affected Version(s)

SP Property extension for Joomla 1.0.0-4.1.3

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.