Directory Traversal Vulnerability in Joomla Extension SP Page Builder by JoomShaper
CVE-2026-81565

6.9MEDIUM

What is CVE-2026-81565?

The vulnerability in the SP Page Builder allows an attacker to exploit a missing directory confinement during media uploads. The folder request parameter can replace the intended destination path, enabling files to be written to any directory beneath the web root, including sensitive directories such as administrator/, templates/, and the site's root directory. While Joomla's PATH input filter prevents upward traversal above the web root, this vulnerability poses significant risks as it may lead to unauthorized file uploads and potential escalation of privileges.

Affected Version(s)

SP Page Builder (Free and Pro) extension for Joomla 4.0.0 - 6.9.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Phil Taylor, mysites.guru
.