Open Mail Relay Vulnerability in T4 Page Builder by Joomlart
CVE-2026-78374
6.9MEDIUM
What is CVE-2026-78374?
The T4 Page Builder extension for Joomla contains a significant vulnerability that allows for an open mail relay through its contact AJAX endpoint. This issue arises in versions prior to 2.3.0, where the 'contact' action can be invoked without any authentication, CSRF token, or captcha protection. Additionally, there is no rate limiting observed, enabling attackers to manipulate the recipient, subject, and body of the email. Emails are sent using the site's configured sender identity, opening the door to potential phishing attacks and email spoofing.
Affected Version(s)
T4 Page Builder extension for Joomla 1.0.0-2.2.0
