PatchSiren

joomshaper.com CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH joomshaper.com CVE published 2026-09-23

CVE-2026-90902

The Easy Store extension for Joomla, versions 1.0.0-3.0.0, contains a high-severity SQL injection vulnerability in its coupon bulk update feature. This vulnerability allows an authenticated administrator to inject malicious SQL syntax, potentially leading to data breaches or system compromise. The vulnerability arises from the direct concatenation of input IDs into raw SQL IN (...) clauses without proper [truncated]

HIGH joomshaper.com CVE published 2026-09-23

CVE-2026-90901

Authenticated, Privileged SQL Injection in Media Image Deletion in Easy Store extension 1.0.0-3.0.0 allows attackers to inject arbitrary SQL statements via a vulnerable media deletion endpoint, posing a high risk to Joomla administrators and defenders. The endpoint fails to properly cast or parameterize the 'ids' parameter, leading to potential data breaches and privilege escalation. Immediate verificatio [truncated]

MEDIUM joomshaper.com CVE published 2026-09-14

CVE-2026-79701

CVE-2026-79701 is a CAPTCHA bypass vulnerability in the SP Page Builder Pro Joomla extension, affecting versions 3.2.6 - 5.6.1p2 and 6.0.0 - 6.9.0. The vulnerability allows unauthenticated attackers to bypass CAPTCHA verification by submitting a 'view_type=module' parameter with an arbitrary token value. This affects instances of the Contact, Opt-in, and Form Builder addons placed inside an SP Page Builde [truncated]

MEDIUM joomshaper.com CVE published 2026-08-12

CVE-2026-67287

The CVE-2026-67287 vulnerability affects Joomla Extension - joomshaper.com - SP Page Builder versions prior to 6.8.0. An unauthenticated attacker can create comments on instances with disabled guest commenting by overriding the setting with user-supplied input. This vulnerability allows for potential exploitation through comment creation, which may lead to information disclosure or other malicious activit [truncated]

MEDIUM joomshaper.com CVE published 2026-08-12

CVE-2026-67286

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-12T15:18:21.613Z and has not been modified since then. This vulnerability affects SP Page Builder versions less than 6.8.0 and allows unauthenticated arbitrary directory creation and file write. The vulnerability has a CVSS score of 6.3 and a severity of MEDIUM. Users of SP Page Builder should asses [truncated]

CRITICAL joomshaper.com CVE published 2026-08-12

CVE-2026-67285

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-12T14:18:33.423Z and has not been modified since then. This critical vulnerability in Joomla Extension SP Page Builder, known as CVE-2026-67285, allows unauthenticated arbitrary local PHP file inclusion. The vulnerability can lead to code execution and potential system compromise. Affected product d [truncated]

HIGH joomshaper.com CVE published 2026-08-07

CVE-2026-66494

CVE-2026-66494: Unauthenticated stored XSS in Joomla Extension SP Page Builder < 6.7.0. The vulnerability allows an unauthenticated attacker to store malicious JavaScript in a Joomla site's database via a single HTTP request, which executes when an administrator opens the SP Page Builder editor. This issue has a CVSS score of 8.7 and is considered HIGH severity. Affected systems require immediate attentio [truncated]

CRITICAL joomshaper.com CVE published 2026-07-27

CVE-2026-65879

CVE-2026-65879 is an unauthenticated mail relay vulnerability in Joomla Extension SP Page Builder versions less than 6.7.1. The issue arises from a hardcoded secret that allows attackers to forge the mail from address of forms, potentially leading to email spoofing and other malicious activities. This vulnerability has a high impact on affected deployments, and users should apply patches or mitigations to [truncated]

HIGH joomshaper.com CVE published 2026-07-27

CVE-2026-65878

CVE-2026-65878 is a HIGH severity vulnerability in Joomla Extension SP Page Builder versions before 6.7.1. The vulnerability allows authenticated users to delete arbitrary files due to improper path validation and ACL checks in the media manager. This could lead to data loss and system compromise if exploited. Users of Joomla Extension SP Page Builder versions before 6.7.1 should update to the latest vers [truncated]

CRITICAL joomshaper.com CVE published 2026-07-27

CVE-2026-65876

CVE-2026-65876 is a critical vulnerability in the Joomla Extension SP Page Builder, specifically affecting versions prior to 6.7.1. The vulnerability allows for unauthenticated SQL injection due to improper validation of catid parameters in the loadMoreArticles endpoint. This issue has been assigned a CVSS score of 9.2, indicating a critical severity level.

CRITICAL joomshaper.com CVE published 2026-07-27

CVE-2026-65766

CVE-2026-65766 is a critical vulnerability in the Joomla Extension SP Page Builder, with a CVSS score of 9.2. The vulnerability is caused by improper validation of order parameters in the Dynamic Content endpoint, leading to an SQL injection vector. This vulnerability affects Joomla Extension SP Page Builder versions prior to 6.7.1. The CVE record was published on 2026-07-27T14:17:00.533Z and has not been [truncated]

HIGH joomshaper.com CVE published 2026-07-13

CVE-2026-57830

CVE-2026-57830 is a high-severity vulnerability in the Joomla extension Helix Ultimate, allowing unauthenticated arbitrary file deletion. The CVE record was published on 2026-07-13T08:16:21.713Z and has not been modified since then. This vulnerability affects Joomla deployments with the Helix Ultimate extension installed, potentially leading to data loss and other security issues. Administrators and users [truncated]

HIGH joomshaper.com CVE published 2026-07-13

CVE-2026-57829

CVE-2026-57829 is a high-severity vulnerability in the Joomla extension Helix Ultimate, allowing unauthenticated stored XSS attacks. This vulnerability has been assigned a CVSS score of 8.7, indicating high severity. Affected administrators should prioritize patching to prevent potential exploitation. The vulnerability allows attackers to inject malicious scripts into the application, potentially leading [truncated]