Authenticated Privileged SQL Injection in SP Page Builder by JoomShaper
CVE-2026-78375

8.6HIGH

What is CVE-2026-78375?

This vulnerability affects JoomShaper's SP Page Builder between versions 5.2.1 and 6.9.0. An attacker can exploit an authenticated privileged SQL injection flaw in the content plugin, specifically via the onContentAfterSave() event. The issue arises from improper sanitization of user-supplied input, allowing attackers to manipulate the WHERE clause of a query executed against the database. As a result, the attacker can potentially access sensitive information within the database, including user credentials and session data, through time-based blind SQL injection tactics.

Affected Version(s)

SP Page Builder (Free and Pro) extension for Joomla 5.2.1 - 6.9.0

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Phil Taylor, mysites.guru
.