Joomla Extension Vulnerability in SP Page Builder by JoomShaper
CVE-2026-81564

7HIGH

What is CVE-2026-81564?

A missing directory confinement flaw in JoomShaper's SP Page Builder allows attackers to exploit the media rename functionality. Due to insufficient validation checks, attackers can rename files throughout the Joomla installation. Specifically, the vulnerability stems from the failure to enforce proper checks between the media identifier and the filesystem path, enabling the alteration of crucial files, including configuration.php, potentially taking the site offline.

Affected Version(s)

SP Page Builder (Free and Pro) extension for Joomla 4.0.0 - 6.9.0

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Phil Taylor, mysites.guru
.